CVE-2023-23903
Summary
| CVE | CVE-2023-23903 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-09 10:15:00 UTC |
| Updated | 2023-08-16 19:44:00 UTC |
| Description | An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console intervention. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nozominetworks | Cmc | All | All | All | All |
| Application | Nozominetworks | Guardian | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NN-2023:7-01 - DoS via SAML configuration in Guardian/CMC before 22.6.2 - CVE-2023-23903 | Product Security Incident Response Portal | MISC | security.nozominetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.