Description
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
References (4)
Core 4
Core References
Product
http://afterlogic.com
Broken Link, Not Applicable
http://aurora.com
Third Party Advisory, US Government Resource, VDB Entry
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H&version=3.1
Exploit, Patch, Third Party Advisory
https://sec.leonardini.dev/blog/cve-2023-43176-rce_aurora_files/
Scores
CVSS v3
8.8
EPSS
0.0171
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (1)
afterlogic/aurora_files
9.7.3
Published
Oct 03, 2023
Tracked Since
Feb 18, 2026