VYPR
Unrated severityNVD Advisory· Published Oct 19, 2023· Updated Sep 12, 2024

CVE-2023-27792

CVE-2023-27792

Description

An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insecure ACLs on subdirectories of IXP Data Easy Install v6.6.14884.0 allow low-privileged users to escalate privileges.

Vulnerability

An issue found in IXP Data Easy Install v.6.6.14884.0 allows privilege escalation due to a lack of proper permissions applied to subdirectories. The vulnerability affects the insecure local filesystem ACLs (CVE‑2023‑27792) as described in the reference [1]. The misconfiguration permits unauthorized access to sensitive directories by users with limited privileges.

Exploitation

An attacker with low-privileged access to the system can navigate the file system and access subdirectories that have not had their ACLs correctly restricted. No additional authentication or user interaction is required beyond local access. The exploit involves enumerating directories and files that should have been locked down but are readable or writable due to the misconfigured permissions.

Impact

Successful exploitation allows an attacker to escalate their privileges on the local system. Depending on the contents of the improperly secured directories, this could lead to disclosure of sensitive configuration data or overwriting files, potentially leading to full compromise of the application’s security controls.

Mitigation

As of the reference publication [1], IXP Data has not released a public fix for CVE‑2023‑27792. The advisory recommends that administrators review and manually correct the filesystem ACLs on subdirectories of the Easy Install installation, ensuring that only authorized users have appropriate permissions. If a patched version becomes available, it should be applied promptly.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.