CVE ID | CVE-2023-4997 |
Publication date | 04 October 2023 |
Vendor | ProIntegra S.A |
Product | UptimeDC |
Vulnerable versions | All below 2.0.0.33940 |
Vulnerability type (CWE) | Missing Authorization (CWE-862) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in UptimeDC software and participated in its coordination. The vulnerability allows every logged in user to change administrator password, subsequently leading to a privilege escalation. The weakness has been confirmed by the vendor and assigned the number CVE-2023-4997. The vulnerability was fixed in version 2.0.0.33940, all below are vulnerable.
Credits
We thank Antoni Kwietniewski from Alior Bank for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.