A CWE-306: Missing Authentication for Critical Function...
High severity
Unreviewed
Published
Sep 14, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 14, 2023
Published to the GitHub Advisory Database
Sep 14, 2023
Last updated
Apr 4, 2024
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change update source, potentially leading to remote
code execution when the attacker force an update containing malicious content.
References