PatchSiren cyber security CVE debrief
CVE-2023-5047 DRD Fleet Leasing CVE debrief
CVE-2023-5047 is a critical SQL injection vulnerability in DRD Fleet Leasing DRDrive. The vulnerability affects DRDrive versions before 20231006 and is rated CVSS 9.8 with network access, no privileges, and no user interaction required. Because the impact is listed as high for confidentiality, integrity, and availability, exposed DRDrive deployments should be prioritized for immediate patching and validation against the vendor-advised fixed version boundary.
- Vendor
- DRD Fleet Leasing
- Product
- DRDrive
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-11-22
- Original CVE updated
- 2026-05-21
- Advisory published
- 2023-11-22
- Advisory updated
- 2026-05-21
Who should care
Organizations running DRD Fleet Leasing DRDrive, especially administrators responsible for internet-facing or broadly reachable instances, should treat this as an urgent remediation item. Security teams should also care if DRDrive is used to store, query, or manage sensitive business data.
Technical summary
The supplied advisory data identifies an improper neutralization of special elements in an SQL command (CWE-89) in DRDrive. NVD lists the affected CPE as drd:drdrive with versions before 2023.10.06. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable issue with no required privileges or user interaction and potentially severe impact if the vulnerable component is exposed.
Defensive priority
Immediate. The combination of a critical CVSS score, remote reachability, no authentication requirement, and high impact justifies urgent remediation.
Recommended defensive actions
- Upgrade DRDrive to version 20231006 or later, consistent with the supplied affected-version boundary.
- Inventory all DRDrive deployments to confirm whether any instance is running a vulnerable version.
- Review network exposure for DRDrive systems and limit access where operationally feasible until patched.
- Check application, database, and web logs for anomalous queries or unexpected database activity around the vulnerable service.
- Validate the vendor or USOM advisory for any additional remediation guidance and confirm the environment is no longer running a vulnerable build.
Evidence notes
This debrief is based only on the supplied NVD record and the referenced USOM advisory links included in the source corpus. The issue description, affected version cutoff, CWE-89 mapping, and CVSS vector/score come from the supplied source item metadata. No exploit details or unsupported remediation claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-5047 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-5047
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-5047 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5047
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0651
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0651
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.