« Back to list

CVE-2023-43762

Status: ModifiedCritical (9.8)—

Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-43762",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-43762",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-25T15:16:41.660352Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:withsecure:f-secure_policy_manager:15.00:*:*:*:*:linux_kernel:*:*"
          ],
          "vendor": "withsecure",
          "product": "f-secure_policy_manager",
          "versions": [
            {
              "status": "affected",
              "version": "15.00"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:withsecure:f-secure_policy_manager:15.00:*:*:*:*:windows:*:*"
          ],
          "vendor": "withsecure",
          "product": "f-secure_policy_manager",
          "versions": [
            {
              "status": "affected",
              "version": "15.00"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:withsecure:policy_manager_proxy:15.00:*:*:*:*:linux_kernel:*:*"
          ],
          "vendor": "withsecure",
          "product": "policy_manager_proxy",
          "versions": [
            {
              "status": "affected",
              "version": "15.00"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:withsecure:policy_manager_proxy:15.00:*:*:*:*:windows:*:*"
          ],
          "vendor": "withsecure",
          "product": "policy_manager_proxy",
          "versions": [
            {
              "status": "affected",
              "version": "15.00"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-09-22T05:15:09.530",
  "references": [
    {
      "url": "https://www.withsecure.com/en/support/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories/cve-2023-43762",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn511",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories/cve-2023-43762",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories/cve-2023-nnn511",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15."
    },
    {
      "lang": "es",
      "value": "Ciertos productos WithSecure permiten la Ejecución Remota de Código No Autenticado a través del servidor web (backend). Esto afecta a WithSecure Policy Manager 15 y Policy Manager Proxy 15."
    }
  ],
  "lastModified": "2026-06-17T06:26:23.440",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:withsecure:f-secure_policy_manager:15.00:*:*:*:*:linux_kernel:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D9F1F8D-83A9-45F3-8663-C74C01680DEF"
            },
            {
              "criteria": "cpe:2.3:a:withsecure:f-secure_policy_manager:15.00:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9339090-9BBC-42D7-8754-A450AB7F51E5"
            },
            {
              "criteria": "cpe:2.3:a:withsecure:policy_manager_proxy:15.00:*:*:*:*:linux_kernel:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAF05F1B-0F21-45E4-B5D6-16E70F60B65F"
            },
            {
              "criteria": "cpe:2.3:a:withsecure:policy_manager_proxy:15.00:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CD6A445-7C2D-43DE-89DC-9B98EB4835FB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}