CVE-2023-41264: Critical severity netwrix usercube vulnerability
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST /api/Deployment/ExportConfiguration and POST /api/Deployment endpoints).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41264.
What is the severity of CVE-2023-41264?
The severity of CVE-2023-41264 is critical with a severity value of 9.8.
What is the affected software of CVE-2023-41264?
The affected software of CVE-2023-41264 is Netwrix Usercube version up to 6.0.215.
How does CVE-2023-41264 impact misconfigured on-premises installations?
CVE-2023-41264 allows authentication bypass on deployment endpoints, leading to privilege escalation in certain misconfigured on-premises installations of Netwrix Usercube.
How can CVE-2023-41264 be fixed?
To fix the vulnerability, ensure that the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields are properly configured in the installation of Netwrix Usercube.