CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-37226

CVSS 9.8v3.1pub. 2024-09-10upd. 2025-05-29

Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-287 (Missing Authentication for a Critical Function) means that specific functionality of the Loftware Spectrum application is accessible without requiring user authentication. An attacker can send a properly crafted network request directly to the vulnerable endpoint, bypassing access control mechanisms. Due to the network vector (AV:N) and the absence of user interaction requirement (UI:N) or privileges (PR:N), the attack can be conducted entirely remotely and without any prior permissions.

Impact

An attacker can gain unauthorized access to sensitive data, modify system content, and cause its unavailability, which corresponds to maximum impact on confidentiality, integrity, and availability (C:H/I:H/A:H).

Mitigation & patch

Loftware Spectrum should be updated to version 4.6 HF14 or later according to the manufacturer's information available in the release notes: https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF14.htm

Who is affected

Loftware Spectrum in versions prior to 4.6 HF14

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Loftware Spectrum

    APP
    Loftware
    4.6< 4.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-37231CRITICAL9.8PL ✓same product

Loftware Spectrum — zakodowane na stałe hasło (Hard-coded Password)

CVE-2023-37227CRITICAL9.8PL ✓same product

Niebezpieczna deserializacja danych w Loftware Spectrum przed wersją 4.6 HF13

CVE-2023-37234CRITICAL9.8PL ✓same product

Loftware Spectrum — niezabezpieczony rejestr JMX umożliwia zdalny dostęp

CVE-2023-37233HIGH8.8same product

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

CVE-2023-37232HIGH7.5same product

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.