CVE-2023-6263

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:networkoptix:nxcloud:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:43

Type Values Removed Values Added
References () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - Vendor Advisory () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - Vendor Advisory
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 8.3

18 Dec 2023, 15:15

Type Values Removed Values Added
Summary An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server. An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

04 Dec 2023, 14:40

Type Values Removed Values Added
References () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - Vendor Advisory
First Time Networkoptix nxcloud
Networkoptix
CPE cpe:2.3:a:networkoptix:nxcloud:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-290

22 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-22 18:15

Updated : 2024-11-21 08:43


NVD link : CVE-2023-6263

Mitre link : CVE-2023-6263

CVE.ORG link : CVE-2023-6263


JSON object : View

Products Affected

networkoptix

  • nxcloud
CWE
CWE-290

Authentication Bypass by Spoofing