Vulnerability Details
Basic Information
| Title | CVE-2023-46669 Elastic Agent / Elastic Endpoint Security local API key disclosure |
|---|---|
| Type | vulnrichment |
| Published | 2025-05-01T12:59:49 |
| Last Seen | 2025-05-01T16:24:08 |
| CVSS Score | 6.2 (MEDIUM) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2023-46669 |
|---|---|
| CWE | CWE-200 |
| Bulletin Family | cve |
Description
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
Impact Assessment
| Base Score | 6.2 |
|---|---|
| Severity | MEDIUM |