CVE-2023-6352

Published Nov 30, 2023

Last updated a year ago

Overview

Description
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-22
9119a7d8-5eab-497f-8521-727c672e3725
CWE-22

Social media

Hype score
Not currently trending

Configurations