CVE-2023-1705 describes a Missing Authorization vulnerability in the Forcepoint F|One SmartEdge Agent on Windows, specifically within the bgAutoinstaller service modules. This flaw affects versions prior to 1.7.0.230330-554. The vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk. An attacker with local, low-privileged access can exploit this with low complexity to achieve Privilege Escalation, Functionality Bypass, and potentially gain full control over the system (Confidentiality, Integrity, and Availability impacts are High). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0.230330-554CPE matchmatch criteria | cpe:2.3:a:forcepoint:one_smartedge_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.