CVE-2023-43017: IBM Security Verify Access man in the middle
Published Jan 9, 2024
·Updated
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.
Affected Software
3 affected components
IBM Security Verify Access Docker<=10.0.0.0 - 10.0.6.1
IBM Security Verify Access Appliance<=10.0.0.0 - 10.0.6.1
IBM Security Verify Access>=10.0.0.0<=10.0.6.1
Remediation
Patch Available
Event History
Jan 9, 2024
CVE Published
via IBM·12:00 AM
Feb 7, 2024
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-43017?
CVE-2023-43017 is classified as a high severity vulnerability due to the potential for privileged user exploitation to enable remote access.
2
How do I fix CVE-2023-43017?
To fix CVE-2023-43017, update IBM Security Verify Access to version 10.0.6.2 or later.
3
Who is affected by CVE-2023-43017?
CVE-2023-43017 affects IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1.
4
What types of products are impacted by CVE-2023-43017?
CVE-2023-43017 impacts IBM Security Verify Access, Security Verify Access Docker, and Security Verify Access Appliance.
5
Can CVE-2023-43017 be exploited remotely?
Yes, CVE-2023-43017 can be exploited remotely by a privileged user to install a malicious configuration file.