Report an incident
Report an incident

Vulnerability in UptimeDC software
04 October 2023 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2023-4997
Publication date 04 October 2023
Vendor ProIntegra S.A
Product UptimeDC
Vulnerable versions All below 2.0.0.33940
Vulnerability type (CWE) Missing Authorization (CWE-862)
Report source Report to CERT Polska

Description

CERT Polska has received a report about vulnerability in UptimeDC software and participated in its coordination. The vulnerability allows every logged in user to change administrator password, subsequently leading to a privilege escalation. The weakness has been confirmed by the vendor and assigned the number CVE-2023-4997. The vulnerability was fixed in version 2.0.0.33940, all below are vulnerable.

Credits

We thank Antoni Kwietniewski from Alior Bank for the responsible vulnerability report.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.