cbcvebase.
CVE-2023-5516
published 2023-11-01

CVE-2023-5516: Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.38%
29.9th percentile
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info, endpoints, backend server, Internal IP. etc., which can potentially expose additional attack surface containing other interesting vulnerabilities.

Affected

2 ranges
VendorProductVersion rangeFixed in
hitachi_energyesoms6.0 – 6.3.13
hitachienergyesoms<= 6.3.13

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.