CVE-2023-27497 is a critical vulnerability affecting SAP Diagnostics Agent versions 720 running on Windows, stemming from missing authentication and input sanitization in the EventLogServiceCollector. This allows an unauthenticated attacker to execute arbitrary malicious scripts on all connected Diagnostics Agents. With a CVSS score of 9.8 (Critical), successful exploitation leads to complete compromise of confidentiality, integrity, and availability of the affected systems. While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
720CPE matchmatch criteria | cpe:2.3:a:sap:diagnostics_agent:720:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.