CVE-2023-23128

MEDIUM

Connectwise - Permissive CORS Policy

Title source: rule
STIX 2.1

Description

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-942
Status published
Products (1)
connectwise/connectwise 22.8.10013.8329
Published Feb 01, 2023
Tracked Since Feb 18, 2026