LiveActive security incident?Get immediate response
CVE Record

CVE-2023-49899: Origin Validation Error in X-Rite MA-T6

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

CVE-2023-49899 is a critical flaw in X-Rite MA-T6 devices. The public CVE states an unauthenticated remote attacker could execute commands because the device does not correctly verify communication origin. That means a reachable affected device could be fully compromised without credentials.

Executive priority

Prioritize discovery and containment now. The flaw is critical and remotely reachable without authentication, but public evidence in the bundle does not confirm exploitation or a named patch.

Technical view

The issue is classified as CWE-346, origin validation error, with CVSS 3.1 score 9.8. The CVE describes unauthenticated network command execution on X-Rite MA-T6. The affected entry lists MA-T6 version 0, with no CPEs and no patch details in the provided sources.

Likely exposure

Exposure is most likely where X-Rite MA-T6 devices are network-reachable from untrusted networks. The affected-version data is sparse, so asset owners should validate exact model and firmware status against vendor guidance.

Exploitation context

The source bundle does not show CISA KEV listing or cited evidence of active exploitation. Treat this as high urgency because the described impact is unauthenticated remote command execution, not because exploitation is proven.

Researcher notes

Do not assume broader X-Rite product impact from this bundle. The affected metadata is limited to MA-T6 version 0 and lacks CPEs. Public analysis should focus on validating asset reachability, firmware status, and vendor-confirmed remediation.

Mitigation direction

  • Identify all X-Rite MA-T6 devices and their firmware versions.
  • Check X-Rite and Claroty guidance for confirmed fixes or mitigations.
  • Restrict MA-T6 access to trusted management networks only.
  • Block internet exposure and unnecessary routed access to affected devices.
  • Monitor device logs and network traffic for unexpected administrative activity.

Validation and detection

  • Confirm whether any deployed asset is X-Rite MA-T6.
  • Compare firmware and product identifiers against vendor guidance.
  • Verify the device is not reachable from the internet.
  • Review firewall rules for unnecessary access to the device.
  • Check for unusual commands, configuration changes, or service restarts.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-346: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2023-49899 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CERTVDE

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2023-49899Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
X-RiteMA-T60unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-346 · source CWE mapping

Origin Validation Error

Origin Validation Error represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.