CVE-2023-5253: Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication.
Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5253?
CVE-2023-5253 has a high severity rating due to the potential for unauthorized access to sensitive asset data.
How do I fix CVE-2023-5253?
To fix CVE-2023-5253, ensure that authentication checks are implemented for the WebSocket channel used in Nozomi Networks Guardian and CMC.
What systems are affected by CVE-2023-5253?
CVE-2023-5253 affects Nozomi Networks Guardian and CMC versions prior to 23.3.0.
Can CVE-2023-5253 be exploited remotely?
Yes, CVE-2023-5253 can be exploited remotely by unauthenticated attackers to access asset data.
Is there a patch available for CVE-2023-5253?
A patch addressing CVE-2023-5253 is available as part of version updates for Nozomi Networks Guardian and CMC.