First published: Wed Sep 27 2023(Updated: )
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
Credit: cna@cyber.gov.il cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Oneidentity Password Manager | >=5.9.7.1<5.11.2 | |
Oneidentity Password Manager | >=5.12.0<5.12.2 | |
>=5.9.7.1<5.11.2 | ||
>=5.12.0<5.12.2 |
upgrade to versions 5.12.2, 5.11.2 or 5.13
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4003 is high with a CVSS score of 6.8.
An unauthenticated attacker with physical access to a workstation can exploit CVE-2023-4003 to upgrade privileges to SYSTEM.
The affected software for CVE-2023-4003 is One Identity Password Manager versions 5.9.7.1 to 5.11.2 and versions 5.12.0 to 5.12.2.
The Common Weakness Enumeration (CWE) ID for CVE-2023-4003 is CWE-250: Execution with Unnecessary Privileges.
To fix CVE-2023-4003, users should update their One Identity Password Manager software to a version that is not affected.