CVE-2023-3786 MEDIUM

CVE-2023-3786: Aures Komet Kiosk Mode access control

Vendor Aures
Product Komet
Weakness CWE-284
Published July 20, 2023
Last update August 2, 2024

CVSS base score

4.3/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-235053 was assigned to this vulnerability.

Key dates

02Disclosure timeline

July 20, 2023 CVE published
August 2, 2024 Record updated