CVE-2023-44324

Severity
9.8CRITICAL
EPSS
0.2%
top 55.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17

Description

Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
ZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability2023-11-17
GHSA
GHSA-6wwh-cvh6-jmg9: Adobe FrameMaker versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass2023-11-17
CVE-2023-44324 (CRITICAL CVSS 9.8) | Adobe FrameMaker Publishing Server | cvebase.io