Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Illumio
Published: 2023-09-26T21:29:36.575Z
Updated: 2024-09-24T13:43:17.802Z
Reserved: 2023-09-25T18:22:12.952Z
Link: CVE-2023-5183
Updated: 2024-08-02T07:52:07.639Z
Status : Modified
Published: 2023-09-27T15:19:42.873
Modified: 2024-11-21T08:41:15.240
Link: CVE-2023-5183
No data.