Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4003


One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.


Published

2023-09-27T15:19:39.847

Last Modified

2024-11-21T08:34:12.223

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Primary
    CWE-250

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oneidentity password_manager < 5.11.2 Yes
Application oneidentity password_manager < 5.12.2 Yes

References