CVE-2023-26150

HIGH7.5EPSS 0.16%

asyncua Improper Authentication vulnerability

Published: 10/3/2023Modified: 2/16/2024

Description

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

Affected packages (2)

  • PyPI/asyncuafrom 0, < 0.9.96
  • PyPI/asyncuafrom 0, < b4106dfd5037423c9d1810b48a97296b59cde513, < 2be7ce80df05de8d6c6ae1ebce6fa2bb7147844a | from 0, < 0.9.96

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (10)