Loading
Generated remediation guidance and an executive summary. No account required.
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
Use CWE-287, Helpsystems vendor hub and Cobalt Strike product page to widen CVE-2022-23317 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-42948, CVE-2022-39197 and CVE-2021-36798 for nearby disclosures in the same product family.