CVE-2023-41706 is a denial-of-service vulnerability affecting Open-Xchange OX App Suite, where unmonitored processing of user-defined drive search expressions can lead to excessive resource consumption and reduced availability. Rated Medium severity (CVSS 6.5), it can be exploited remotely with low complexity by a low-privileged attacker to cause a high impact on availability. There are no known public exploits, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:* | ||
> 7.6.3, < 7.10.6CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:* | ||
> 7.10.6, < 8.20CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:-:*:*:*:*:*:* | ||
7.6.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:open-xchange_appsuite:7.6.3:patch_release_3464:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.