Vulnerabilities > CVE-2023-3897 - Information Exposure Through Discrepancy vulnerability in 42Gears Suremdm 6.31

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
42gears
CWE-203

Summary

Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version 

Vulnerable Configurations

Part Description Count
Application
42Gears
1

Common Weakness Enumeration (CWE)