Cyber Resilience

CVE-2023-1160

Agentejo Cockpit ≤ 2.3.9

Public PoC
Published
03 March 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0035 28th percentile
Risk Priority 43 floored blend · peak EPSS

Summary

CVE-2023-1160 is a medium-severity Use of Platform-Dependent Third Party Components (CWE-1103) vulnerability in Agentejo Cockpit. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 28th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-4825Same product: Agentejo Cockpit
CVE-2023-4433Same product: Agentejo Cockpit
CVE-2023-0759Same product: Agentejo Cockpit
CVE-2025-7053Same product: Agentejo Cockpit
CVE-2023-4321Same product: Agentejo Cockpit
CVE-2023-37649Same product: Agentejo Cockpit
CVE-2020-35131Same product: Agentejo Cockpit
CVE-2023-4395Same product: Agentejo Cockpit
CVE-2023-4451Same product: Agentejo Cockpit
CVE-2023-1313Same product: Agentejo Cockpit

Affected Assets

agentejo
cockpit
≤ 2.3.9

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V15.1.4
  • V15.2.5

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

GV.SC-01 partial match
prevents

Supply-chain program can require cross-platform evaluation criteria for third-party components.

GV.SC-05 partial match
prevents

Contractual requirements can mandate platform-portability or equivalent functionality specifications.

GV.SC-07 partial match
prevents

Understanding supplier-product risks includes platform-dependency and compatibility issues.

ID.AM-02 partial match
prevents

Software inventory enables tracking of third-party components and their platform coverage.

ID.AM-04 partial match
prevents

Supplier-service inventory surfaces external components whose platform limitations affect the organization.

ID.AM-08 partial match
prevents

Lifecycle management includes evaluating third-party component suitability across target platforms.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

mitigates

Supplier-relationship controls can require vendors to provide cross-platform support or equivalent functionality.

mitigates

Supplier agreements can mandate platform-independence or portability clauses for third-party components.

mitigates

ICT supply-chain management can identify and mitigate risks from platform-dependent third-party components.

mitigates

Ongoing monitoring of supplier services can detect and drive remediation of platform-dependency issues.

degrades

Secure SDLC practices can include portability and cross-platform testing requirements for third-party components.

prevents

Application security requirements can specify platform-independence or equivalent functionality across target platforms.

References