Skip to content

CVE-2023-3842 | EasyInventory

A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:Program Files (x86)EasyInventoryEasy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-235193 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way..This CVE has a CVSS3.1 score of 7.8 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-3842
CVE StatePUBLISHED
BaseScore7.8
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
VersionNA

References for CVE-2023-3842 :
https://vuldb.com/?id.235193
https://vuldb.com/?ctiid.235193

Metric TypeMetric Score
AttackVector(AV)NA
AttackComplexity(AC)NA
PrivilegesRequired(PR)NA
UserInteraction(UI)NA
Scope(S)NA
Confidentiality(C)NA
Availability(A)NA
Integrity(I)NA