Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-37378

20
FAUCET Score

CVE-2023-37378 describes an access control vulnerability in Nullsoft Scriptable Install System (NSIS) versions prior to 3.09, specifically affecting uninstaller directories. This medium-severity vulnerability (CVSS 5.3) is network-exploitable with low attack complexity, potentially leading to low integrity impact without affecting confidentiality or availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, notably in a Siemens product advisory.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.09CPE matchmatch criteria
cpe:2.3:a:nullsoft:nullsoft_scriptable_install_system:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.89%
Probability of exploitation in next 30 days
EPSS Percentile
55.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0089 is in the 35th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

lists.debian.org / debian-lts-announce/2024/09/msg00013.html
sf.net / p/nsis/bugs/1296
Issue TrackingPermissions Required
github.com / kichik/nsis/commit/281e2851fe669d10e0650fc89d0e7fb74a598967
Patch
github.com / kichik/nsis/commit/409b5841479c44fbf33a6ba97c1146e46f965467
Patch
github.com / kichik/nsis/commit/c40cf78994e74a1a3a381a850c996b251e3277c0
Patch
lists.debian.org / debian-lts-announce/2023/07/msg00005.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/A65FBUMHLZ7GBV3VDKUB5EK3A7X2UUWK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OZPAAU57IA3NP6UOUXNBUQBAYK3JB2IM
nsis.sourceforge.io / Docs/AppendixF.html
Release Notes
sourceforge.net / p/nsis/news/2023/07/nsis-309-released
Release Notes