CVE-2023-2538
A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 allows an attacker to retrieve the private key of the TLS certificate in use by the BMC via forced browsing.
An unauthenticated remote attacker would be able to perform Man-in-the-Middle (MitM) attacks against victims that access the web interface through HTTPS.
July 5, 2023
The vulnerability affects: Tyan S5552 BMC version 3.00
CVE-2023-2538
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
5.8
The affected component has reached end of life. It is suggested to replace it with a supported equivalent.
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

