AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-28346

HIGH · CVSS 7.3 EPSS 0.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-05-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.3. It affects Windows. It may be remotely exploitable.

CVE
CVE-2023-28346
Severity
HIGH
CVSS
7.3
EPSS
0.88%
Windows

Original NVD Description

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this access. Remote attackers can interact with private pages on the web server, enabling them to perform privileged actions such as logging into the console and changing console settings if they have valid credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)