CVE-2023-26071

An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:harpaitalia:mcuboict:*:*:*:*:*:*:*:*

History

19 Feb 2025, 16:15

Type Values Removed Values Added
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - Broken Link () https://www.gruppotim.it/it/footer/red-team.html - Broken Link

05 Apr 2023, 01:21

Type Values Removed Values Added
CPE cpe:2.3:a:harpaitalia:mcuboict:*:*:*:*:*:*:*:*
CWE CWE-203
First Time Harpaitalia
Harpaitalia mcuboict
References
  • (MISC) https://vuldb.com/?id.224303 - Third Party Advisory
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - (MISC) https://www.gruppotim.it/it/footer/red-team.html - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

Information

Published : 2023-03-28 20:15

Updated : 2025-02-19 16:15


NVD link : CVE-2023-26071

Mitre link : CVE-2023-26071


JSON object : View

Products Affected

harpaitalia

  • mcuboict
CWE
CWE-203

Observable Discrepancy