6.1
CVSSv3

CVE-2023-29656

Published: 06/07/2023 Updated: 12/07/2023
CVSS v3 Base Score: 6.1 | Impact Score: 4.7 | Exploitability Score: 1.3
VMScore: 0

Vulnerability Summary

An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all ingress or egress traffic in the entire infrastructure where darktrace agents are deployed.

Vulnerable Product Search on Vulmon Subscribe to Product

darktrace threat visualizer

Github Repositories

alexa

[Disclosure for CVE-2023-29656] Vulnerability ID: CVE-2023-29656 Title: Authorization Issue associated with Darktrace Mobile App Who: Marius Petrea @rami_marius Abstract: An authorization issue associated with the Darktrace Mobile App has been identified If running affected Darktrace Threat Visualiser versions, this vulnerability could prevent users disabled during that time f