Cyber Resilience

CVE-2023-43621

Schollz Croc ≤ 9.6.5

Public PoC
Published
20 September 2023
Modified
21 November 2024
CVSS Score v3.1 4.7
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0029 21th percentile
Risk Priority 37 floored blend · peak EPSS

Summary

CVE-2023-43621 is a medium-severity an unspecified weakness vulnerability in Schollz Croc. Its CVSS base score is 4.7 (Medium).

Operationally, ranked at the 21th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-43619Same product: Schollz Croc
CVE-2023-43618Same product: Schollz Croc
CVE-2023-43616Same product: Schollz Croc
CVE-2023-43620Same product: Schollz Croc
CVE-2023-43617Same product: Schollz Croc

Affected Assets

schollz
croc
≤ 9.6.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References