CVE-2023-6023 is a high-severity Local File Inclusion (LFI) vulnerability affecting VertaAI ModelDB, allowing an unauthenticated attacker to read arbitrary files on the server's filesystem by manipulating the artifact_path URL parameter. With a CVSS score of 7.5, this vulnerability presents a high risk due to its low attack complexity and complete confidentiality impact. While not currently on the KEV catalog or showing active exploitation, public Nuclei templates exist, indicating readily available exploit code. Despite the lack of social media discussion or media coverage, its high EPSS and FAUCET Risk Score highlight its significant potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:vertaai:modeldb:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.