CVE-2023-3425

MEDIUM

M-files Classic Web < 23.2 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (3)
m-files/classic_web 23.2
m-files/classic_web < 23.2
m-files/classic_web < 23.6.12695.3
Published Aug 25, 2023
Tracked Since Feb 18, 2026