CVE-2023-4003: One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalation
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4003?
The severity of CVE-2023-4003 is high with a CVSS score of 6.8.
How can an attacker exploit the vulnerability (CVE-2023-4003)?
An unauthenticated attacker with physical access to a workstation can exploit CVE-2023-4003 to upgrade privileges to SYSTEM.
What is the affected software for CVE-2023-4003?
The affected software for CVE-2023-4003 is One Identity Password Manager versions 5.9.7.1 to 5.11.2 and versions 5.12.0 to 5.12.2.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-4003?
The Common Weakness Enumeration (CWE) ID for CVE-2023-4003 is CWE-250: Execution with Unnecessary Privileges.
Is there a fix available for CVE-2023-4003?
To fix CVE-2023-4003, users should update their One Identity Password Manager software to a version that is not affected.