CERT-In Vulnerability Note
CIVN-2023-0365
Improper Authentication Vulnerability in ADiTaaS
Original Issue Date:December 18, 2023
Severity Rating: HIGH
Systems Affected
Overview
A vulnerability has been reported in ADiTaaS version 5.1 which could allow a remote attacker to gain admin level access and completely compromise the targeted platform.
Description
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable platform.
Successful exploitation of this vulnerability could allow the attacker to gain full access to the customers' data and completely compromise the targeted platform.
Credit
This vulnerability is reported by Eaton Zveare.
Solution
- Upgrade to ADiTaaS version 5.1.1 or later.
Vendor Information
ADiTaaS
https://www.aditaas.com/aditaas/
References
ADiTaaS
https://www.aditaas.com/aditaas/
CVE Name
CVE-2023-6483
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|