VYPR
Unrated severityNVD Advisory· Published Jul 6, 2023· Updated Nov 19, 2024

CVE-2023-29656

CVE-2023-29656

Description

An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all ingress or egress traffic in the entire infrastructure where darktrace agents are deployed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper authorization in Darktrace Mobile App (Android) prior to 6.0.15 allows disabled users to control antigena actions, potentially blocking all network traffic.

Vulnerability

The vulnerability is an improper authorization issue in the Darktrace Mobile App for Android, affecting Darktrace Threat Visualiser versions between 6.0.0 and 6.0.15 [1]. When a user account is disabled in the Threat Visualiser web console, the mobile app session does not automatically terminate, allowing the disabled user to retain access. This enables them to perform actions such as controlling "antigena" actions (block/unblock traffic) from the mobile app.

Exploitation

An attacker needs a valid user account that has been previously authorized on the mobile app. The attacker then requests that the account be disabled by a higher-privilege user (or the account becomes disabled for other reasons). After the account is disabled, the attacker can still log in to the mobile app using the same credentials and continue to access sensitive information and perform actions, including antigena actions that can block or unblock network traffic.

Impact

Successful exploitation allows a disabled or low-privilege user to control antigena actions, potentially blocking all ingress or egress traffic in the entire infrastructure where Darktrace agents are deployed, leading to a denial of service (shutdown). Additionally, the attacker can access sensitive information and perform other unauthorized actions within the app.

Mitigation

The vendor, Darktrace, resolved this issue in version 6.0.15 of the Darktrace Mobile App [1]. Users should update to version 6.0.15 or later. No workarounds are mentioned in the available references.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.