Record summary

CVE-2023-22232 has a selected CVSS score of 5.3 (medium); EIP currently links 2 catalogued exploits and 1 Nuclei template.

Description

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 11.4.5affected
Through 12.1.5affected
Through Noneaffected

Proofs of concept

2

Catalogued exploits

ExploitDBAdobe Connect 10 - Username DisclosureExploitDB exploitby h4shurNot analyzed1 file
ExploitDB

PoC details
ExploitDBAdobe Connect 11.4.5 - Local File DisclosureExploitDB exploitby h4shurNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAdobe Connect < 12.1.5 - Local File DisclosureCVSS 5.3

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction

Impact

Unauthenticated attackers can exploit improper access control to download arbitrary files through the system/download endpoint, potentially accessing sensitive Adobe Connect meeting recordings and configuration files.

Remediation

Update Adobe Connect to version 12.1.5 or later that implements proper access control checks for the system/download functionality.

WeaknessesCWE-284
Authors0xr2r
Template tagspacketstormcve2023cveadobelfddownloadvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*
Shodan: title:"Adobe Connect"
Shodan: http.title:"openvpn connect"
FOFA: title="openvpn connect"
Google: intitle:"openvpn connect"

Source: ProjectDiscovery

References

3