CVE-2023-37537: HCL AppScan Presence deployed as Windows service might be vulnerable to an Unquoted Service Path vulnerability
Published Oct 17, 2023
·Updated
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
Affected Software
1 affected component
hcltech Appscan Presence<=2.1.37
Event History
Oct 17, 2023
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverity
Data Sourced
03:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this HCL AppScan Presence vulnerability?
The vulnerability ID for this HCL AppScan Presence vulnerability is CVE-2023-37537.
2
What is the severity of CVE-2023-37537?
CVE-2023-37537 has a severity rating of 7.8 (high).
3
What is the affected software for CVE-2023-37537?
The affected software for CVE-2023-37537 is HCL AppScan Presence version up to and inclusive of 2.1.37.
4
What is the impact of CVE-2023-37537?
CVE-2023-37537 may allow a local attacker to gain elevated privileges.
5
Is there a fix available for CVE-2023-37537?
Yes, HCL AppScan Presence users should update to a version higher than 2.1.37 to fix CVE-2023-37537.