CVE-2023-5935: Missing authentication for local web interface in Arc before v1.6.0
When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.
A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5935?
CVE-2023-5935 is considered a high severity vulnerability due to its potential for local exploitation without authentication.
How do I fix CVE-2023-5935?
To fix CVE-2023-5935, update Arc to version 1.6.0 or later, which addresses the authentication issue in the local web interface.
What is the impact of CVE-2023-5935?
The impact of CVE-2023-5935 allows a local attacker to misuse the unprotected web interface for malicious activities.
Who is affected by CVE-2023-5935?
CVE-2023-5935 affects users of Arc versions prior to 1.6.0.
Is there a workaround for CVE-2023-5935?
Currently, there is no known workaround for CVE-2023-5935; upgrading to the patched version is recommended.