CVE-2023-4296
Estado: ModificadaMedia (6.1)—
If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.76%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://packetstormsecurity.com/files/174703/PTC-Codebeamer-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2023/Sep/10
- https://codebeamer.com/cb/wiki/31346480
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-241-01
- http://packetstormsecurity.com/files/174703/PTC-Codebeamer-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2023/Sep/10
- https://codebeamer.com/cb/wiki/31346480
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-241-01
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-4296",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-4296",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-16T21:20:33.944438Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "PTC",
"product": "Codebeamer",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "v22.10-SP7"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "v22.04-SP5"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "v21.09-SP13"
},
{
"status": "unaffected",
"version": "2.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-08-29T22:15:09.297",
"references": [
{
"url": "http://packetstormsecurity.com/files/174703/PTC-Codebeamer-Cross-Site-Scripting.html",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://seclists.org/fulldisclosure/2023/Sep/10",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://codebeamer.com/cb/wiki/31346480",
"tags": [
"Vendor Advisory"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-241-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://packetstormsecurity.com/files/174703/PTC-Codebeamer-Cross-Site-Scripting.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2023/Sep/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://codebeamer.com/cb/wiki/31346480",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-241-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device."
},
{
"lang": "es",
"value": "?Si un atacante engaña a un usuario administrador de PTC Codebeamer para que haga clic en un vínculo malicioso, puede permitir que el atacante inyecte código arbitrario para que se ejecute en el navegador del dispositivo de destino."
}
],
"lastModified": "2026-06-17T06:37:31.060",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8842BD8-5ADE-4F4C-892B-C7FD0BD00549"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A96C543-780C-4FB8-9B66-E3A970284157"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "869FDFD2-B254-46F1-977C-8C45FC53CF4C"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E162A5AA-DF07-4DB9-A0ED-15CD181B3E8B"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61E616EF-4DD8-4F24-8132-069D1839CC44"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E1FFA2A-5A02-4D3E-AF1A-49F9CB751B29"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EC6A60D-1117-45A3-B64F-6A3C99CCCBF2"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82586B4B-1876-4F6A-903A-B89A50CB13DC"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF54ED5C-B686-4036-8EC4-C2C65D4463FD"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8162D88-A7D0-4BC0-A2D9-D83EC620C009"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE271018-6A6F-4CDD-97AA-12F8A9DE9640"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21A2D6ED-17D8-4DAD-9775-02419D79DD3F"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A099E310-FBA2-4EB1-BD86-C52686E7FA89"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:21.09.0:sp9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0291CE0C-97E3-4933-9B13-6DBB616DAA60"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "334D6C73-8DED-4C77-9222-5534D1F3503D"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F517B94-96C4-4FD0-BB84-73CA2BA0F88B"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65EA30F3-F924-42B3-BFCC-875411C0A7C7"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42357940-98B9-4966-9B85-E5AB495560A6"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB8DB5F9-1972-4F06-9060-E95F8C462681"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.04.0:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AD9CDC5-D62C-4CC4-9328-2C0E41300CDD"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A54ADF57-985E-41AB-B1DF-77E9303531E8"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F94411ED-3CDA-4432-8487-2EE2DD072D6D"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4050B8C-FBA8-48CA-AF45-BC7C70235E37"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19490284-BC6A-45A0-B68D-743E139EB067"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5CF8652-238F-4442-9AA2-B8A6FD9B681C"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC9DEE58-BD1A-47DB-918B-CE1A1D7A7866"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8948D8AB-8392-4CD8-8F8B-F59410A37BBF"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3E14B5E-A1CF-402C-B56A-C745DE28BF91"
},
{
"criteria": "cpe:2.3:a:intland:codebeamer:22.10.0:sp8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B1F1CCA-B937-4AFB-8363-554D74DE71BD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}