CVE-2023-37306

HIGH

Misp-project Malware Information Shar... - Error Information Exposure

Title source: rule
STIX 2.1

Description

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
misp-project/malware_information_sharing_platform 2.4.172
Published Jun 30, 2023
Tracked Since Feb 18, 2026