« Volver al listado

CVE-2023-3406

Estado: ModificadaMedia (6.5)—

Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3406",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-3406",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-28T18:28:51.404395Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@m-files.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@m-files.com",
      "affectedData": [
        {
          "vendor": "M-Files",
          "product": "M-Files Web",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "23.6.12695.3",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "23.2.12340.14"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-08-25T09:15:08.850",
  "references": [
    {
      "url": "https://empower.m-files.com/security-advisories/CVE-2023-3406",
      "source": "security@m-files.com"
    },
    {
      "url": "https://product.m-files.com/security-advisories/cve-2023-3406/",
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-3406",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@m-files.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server"
    },
    {
      "lang": "es",
      "value": "Un problema de path traversal en las versiones de M-Files Classic Web, el cual afecta a las versiones inferiores a 23.6.12695.3 y a las versiones de lanzamiento del servicio LTS inferiores a 23.2 LTS SR3. Esta vulnerabilidad permite a un usuario autenticado leer algunos archivos restringidos en el servidor web."
    }
  ],
  "lastModified": "2026-06-17T06:14:00.680",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:m-files:classic_web:*:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89B60851-49D1-40DA-A600-658BCC986BF6",
              "versionEndExcluding": "23.2"
            },
            {
              "criteria": "cpe:2.3:a:m-files:classic_web:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE7A65F9-84AD-47E9-8C64-3585D5855FEA",
              "versionEndExcluding": "23.6.12695.3"
            },
            {
              "criteria": "cpe:2.3:a:m-files:classic_web:23.2:-:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E66A68C-65E6-48E9-97DD-621B4B73D975"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@m-files.com"
}