CVE-2023-3655
Estado: ModificadaAlta (7.5)—
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP endpoint exposed to the network.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.57%
- Percentil entre todas las CVEs puntuadas: 45
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-749
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-3655",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-3655",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-17T15:04:03.031000Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "office@cyberdanube.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "office@cyberdanube.com",
"affectedData": [
{
"vendor": "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH",
"product": "cashIT! - serving solutions.",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "03.A06rks 2023.02.37"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-10-03T08:15:35.680",
"references": [
{
"url": "https://doi.org/10.35011/ww2q-d522",
"tags": [
"Technical Description"
],
"source": "office@cyberdanube.com"
},
{
"url": "https://www.cashit.at/",
"tags": [
"Product"
],
"source": "office@cyberdanube.com"
},
{
"url": "https://doi.org/10.35011/ww2q-d522",
"tags": [
"Technical Description"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cashit.at/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "office@cyberdanube.com",
"description": [
{
"lang": "en",
"value": "CWE-749"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "cashIT! - serving solutions. Devices from \"PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH\" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP endpoint exposed to the network.\n"
},
{
"lang": "es",
"value": "cashIT! - serving solutions. Los dispositivos desde \"PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH\" hasta 03.A06rks 2023.02.37 se ven afectados por métodos peligrosos que permiten filtrar la base de datos (configuraciones del sistema, cuentas de usuario,...). Esta vulnerabilidad puede ser provocada por un endpoint HTTP expuesto a la red."
}
],
"lastModified": "2026-06-17T06:14:33.410",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cashit:cashit\\!:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "038B664A-EFF6-480B-B33D-82D66205C2B9",
"versionEndIncluding": "03.a06rks_2023.02.37"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "office@cyberdanube.com"
}