CVE-2023-6910: Uncontrolled Resource Consumption in M-Files Server
Published Dec 20, 2023
·Updated
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
Affected Software
1 affected component
M-Files M-Files server<23.12.13195.0
Remediation
Information
Update to patched version.
Event History
Dec 20, 2023
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6910?
CVE-2023-6910 has a severity level that indicates it can lead to uncontrolled resource consumption and service denial.
2
How do I fix CVE-2023-6910?
To fix CVE-2023-6910, upgrade M-Files Server to version 23.12.13195.0 or later.
3
What kind of attack can exploit CVE-2023-6910?
An authenticated attacker can exploit CVE-2023-6910 to exhaust the server's storage space.
4
Which versions of M-Files Server are affected by CVE-2023-6910?
CVE-2023-6910 affects M-Files Server versions prior to 23.12.13195.0.
5
What is the impact of not addressing CVE-2023-6910?
Failing to address CVE-2023-6910 may result in the M-Files Server being unable to serve requests due to storage exhaustion.