Back to overview

CVE-2023-5183

CRITICAL
9.9
CVSS 3.1
Description
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.  

Metadata

CVE ID
CVE-2023-5183
State
PUBLISHED
Assigner
Illumio
Reserved
2023-09-25 18:22 UTC
Published
2023-09-26 21:29 UTC
Last updated
2024-09-24 13:43 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
Illumio / Core PCE
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Illumio Core PCE Linux 19.3.0 ≤ 19.3.6, 21.2.0 ≤ 21.2.7, 21.5.0 ≤ 21.5.35, 22.2.0 ≤ 22.2.41 …
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview