PatchSiren cyber security CVE debrief
CVE-2023-35067 Infodrom Software CVE debrief
CVE-2023-35067 is a high-severity information disclosure issue in Infodrom E-Invoice Approval System before v20230701. According to the published description, the product stores a password in plaintext, which can allow sensitive strings to be read from an executable. The NVD record rates the issue as network-reachable, no-authentication, no-user-interaction, with high confidentiality impact.
- Vendor
- Infodrom Software
- Product
- E-Invoice Approval System
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-25
- Original CVE updated
- 2024-11-21
- Advisory published
- 2023-07-25
- Advisory updated
- 2024-11-21
Who should care
Organizations running Infodrom E-Invoice Approval System, especially deployments still on versions earlier than v20230701. Security teams responsible for application binaries, release artifacts, and secret management should treat this as a credential exposure risk.
Technical summary
The vulnerability is described as plaintext storage of a password that enables read access to sensitive strings within an executable. NVD maps the issue to CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a remote, low-complexity disclosure problem with no integrity or availability impact. NVD also lists CWE-522 and the advisory reference lists CWE-256.
Defensive priority
High for any environment still running affected builds. The issue is easy to reach in principle, has no required privileges or user interaction, and can expose sensitive secrets embedded in software artifacts.
Recommended defensive actions
- Upgrade Infodrom E-Invoice Approval System to v20230701 or later.
- Inventory deployed instances and confirm which hosts still run pre-v20230701 builds.
- Treat any exposed password as compromised and rotate related credentials.
- Review build and packaging processes to ensure secrets are never embedded in executables or release artifacts.
- Scan internal binaries and artifact repositories for plaintext credentials as part of remediation validation.
Evidence notes
This debrief is based only on the supplied NVD CVE record and the linked USOM advisory. The NVD record states the affected range as before v20230701 and provides CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The supplied metadata also lists secondary weakness mappings CWE-256 and CWE-522. No KEV entry was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-35067 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-35067
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-35067 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-35067
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0419
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.