CVE-2023-42261: High severity opensecurity mobile security framework vulnerability
DISPUTED Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Other sources
Withdrawn Advisory This advisory has been withdrawn because the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Original Description Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-42261.
What is the severity of CVE-2023-42261?
The severity of CVE-2023-42261 is high with a CVSS score of 7.5.
What is the affected software?
The affected software is Mobile Security Framework (MobSF) up to version 3.7.6 and version 3.7.8 beta.
What is the vendor's position on this vulnerability?
The vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment.
Are there any fixes or patches available for this vulnerability?
There are no official fixes or patches available at this time.