CVE-2023-4177 is an information disclosure vulnerability affecting EmpowerID up to version 7.205.0.0, specifically within its Multi-Factor Authentication Code Handler. The CVSS score of 5.7 (Medium) indicates that an attacker with low privileges and network access could potentially disclose sensitive information, though the attack complexity is rated as high. While the vulnerability is considered difficult to exploit and no public exploit code or active exploitation has been observed, upgrading to EmpowerID version 7.205.0.1 is recommended to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.205.0.0CPE matchmatch criteria | cpe:2.3:a:empowerid:empowerid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.