CVE-2023-6263 Information

Description

An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

Reference

https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing

Share on: