CVE-2023-46596
Estado: AnalizadaMedia (6.1)—
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-46596",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-46596",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-22T19:21:29.256608Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security.vulnerabilities@algosec.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 0.4
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security.vulnerabilities@algosec.com",
"affectedData": [
{
"vendor": "Algosec",
"product": "Algosec FireFlow",
"versions": [
{
"status": "affected",
"version": "A32.20, A32.50, A32.60"
}
],
"platforms": [
"64 bit",
"Linux"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-15T06:15:45.453",
"references": [
{
"url": "https://www.algosec.com/docs/en/cves/Content/tech-notes/cves/cve-2023-46596.htm",
"tags": [
"Vendor Advisory"
],
"source": "security.vulnerabilities@algosec.com"
},
{
"url": "https://www.algosec.com/docs/en/cves/Content/tech-notes/cves/cve-2023-46596.htm",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security.vulnerabilities@algosec.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nImproper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)\n\n"
},
{
"lang": "es",
"value": "La validación de entrada incorrecta en el editor de flujo de trabajo Algosec FireFlow VisualFlow a través del campo Nombre, Descripción y Archivo de configuración en la versión A32.20, A32.50, A32.60 permite a un atacante iniciar un ataque XSS inyectando scripts ejecutables maliciosos en el código de la aplicación. Corregido en la versión A32.20 (b600 y superior), A32.50 (b430 y superior), A32.60 (b250 y superior)"
}
],
"lastModified": "2026-06-17T06:31:10.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:algosec:fireflow:a32.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F57DA17-E133-43D9-AC12-60CBD0FBC253"
},
{
"criteria": "cpe:2.3:a:algosec:fireflow:a32.50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3144E50-DB4B-4342-8147-7604003EC8D7"
},
{
"criteria": "cpe:2.3:a:algosec:fireflow:a32.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DF7FEFC-C3D7-490D-BE7C-1FE5EBB3B7F2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security.vulnerabilities@algosec.com"
}