In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/Skr11lex/CVE-2023-33477 | third party advisory |