Security readout for executives and security teams
Plain-English summary
Priority web V22.0 has an authorization weakness where a logged-in low-privilege user may reach application functions they should not be allowed to use. The published impact is moderate, with limited confidentiality, integrity, and availability effects. The supplied sources do not name a patch, workaround, or active exploitation.
Executive priority
Treat this as a moderate business risk if Priority web V22.0 supports sensitive workflows. It is not an unauthenticated internet-takeover issue based on the sources, but it can weaken internal role separation and audit controls.
Technical view
The issue is an IDOR/authorization bypass in Priority web V22.0. A low-privileged authenticated user may alter a workflow or navigation parameter to access role-restricted functions. CVSS 3.1 is 5.5 with low confidentiality, integrity, and availability impacts. No CWE, fixed version, or vendor workaround is provided in the supplied data.
Likely exposure
Organizations running Priority web V22.0 where low-privilege authenticated users can reach the web interface. CVSS lists adjacent attack vector, but the narrative references web interface login; internet exposure is not confirmed by the supplied sources.
Exploitation context
The CVE is not listed as KEV, and the supplied sources do not report active exploitation. Exploitation requires prior low-privilege access and targets missing server-side authorization checks rather than initial compromise.
Researcher notes
Evidence is limited to the CVE description, CVSS vector, affected product, and a government advisory reference. The record does not provide exploit status, patch details, affected configurations beyond V22.0, or CWE mapping. Validate through authorized role-based testing only.
Mitigation direction
- Identify Priority web V22.0 instances and confirm vendor guidance for fixed builds.
- Restrict Priority web access to trusted networks and approved users.
- Review user roles and remove unnecessary low-privilege accounts.
- Monitor Priority web logs for denied-function access followed by unusual successful access.
- Ask the vendor whether authorization fixes or configuration mitigations are available.
Validation and detection
- Inventory Priority web versions and confirm whether V22.0 is deployed.
- Review application roles against users who can access the web interface.
- Test authorization boundaries using approved accounts in a controlled environment.
- Check logs for unexpected access to functions outside assigned roles.
- Track the gov.il advisory and CVE record for patch or mitigation updates.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2022-23173 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L2.13.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source materials
- CVE List V5 sourceCVE List V5
- https://www.gov.il/en/Departments/faq/cve_advisoriesCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
