Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2
Vulnerability Description
An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining data that would normally be not accessible in the Query and Assertions functions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-24471
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was found by Stefano Libero of Nozomi Networks Product Security team during a scheduled internal VAPT testing session.
More from Nozomi Networks
View All →Affected Vendor
Nozomi Networks
View all reports →