CVE-2023-4392 is a problematic vulnerability affecting Control iD Gerencia Web version 1.30, specifically within its Cookie Handler component. This flaw allows for the cleartext storage of sensitive information, potentially leading to data exposure. Rated with a CVSS score of 5.3 (Medium), exploitation requires low privileges and has high impact on confidentiality, though attack complexity is high. While the exploit has been publicly disclosed, its exploitation is considered difficult, and there is no evidence of active exploitation, exploit code in common frameworks, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.30CPE matchmatch criteria | cpe:2.3:a:assaabloy:control_id_gerencia_web:1.30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.