« Volver al listado

CVE-2023-3654

Estado: ModificadaCrítica (9.8)—

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3654",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "office@cyberdanube.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.4,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "office@cyberdanube.com",
      "affectedData": [
        {
          "vendor": "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH",
          "product": "cashIT! - serving solutions.",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "03.A06rks 2023.02.37"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-03T09:15:10.247",
  "references": [
    {
      "url": "https://doi.org/10.35011/ww2q-d522",
      "tags": [
        "Technical Description"
      ],
      "source": "office@cyberdanube.com"
    },
    {
      "url": "https://www.cashit.at/",
      "tags": [
        "Product"
      ],
      "source": "office@cyberdanube.com"
    },
    {
      "url": "https://doi.org/10.35011/ww2q-d522",
      "tags": [
        "Technical Description"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cashit.at/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "office@cyberdanube.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "cashIT! - serving solutions. Devices from \"PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH\" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.\n"
    },
    {
      "lang": "es",
      "value": "cashIT! - serving solutions. Los dispositivos desde \"PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH\" hasta 03.A06rks 2023.02.37 se ven afectados por una omisión de origen a través del encabezado del host en una solicitud HTTP. Esta vulnerabilidad puede ser provocada por un endpoint HTTP expuesto a la red."
    }
  ],
  "lastModified": "2026-06-17T06:14:33.287",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cashit:cashit\\!:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "038B664A-EFF6-480B-B33D-82D66205C2B9",
              "versionEndIncluding": "03.a06rks_2023.02.37"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "office@cyberdanube.com"
}