CVE-2023-35800: Medium severity Stormshield Endpoint Security vulnerability
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35800.
What is the title of the vulnerability?
The title of the vulnerability is 'Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions.'
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 4.3.
What is the affected software?
The affected software is Stormshield Endpoint Security Evolution versions 2.0.0 through 2.4.2.
How can this vulnerability be exploited?
An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, potentially granting access to information reserved for administrators.