Intelligence View
⚡ tsecurity.de Intelligence
CVE-2023-40235 | ArchiMate Archi up to 5.0.x Project File Parser XMLNS Remote Code Execution (Issue 946 / EUVD-2023-44832)
A vulnerability was found in ArchiMate Archi up to 5.0.x. It has been classified as critical. This affects an unknown part of the component Project File…
A vulnerability was found in ArchiMate Archi up to 5.0.x. It has been classified as critical. This affects an unknown part of the component Project File Parser. The manipulation of the argument XMLNS leads to Remote Code Execution.
This vulnerability is listed as CVE-2023-40235. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
This vulnerability is listed as CVE-2023-40235. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2023-40235
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2024-10-09T20:13:43.448317Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com