AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2023-38646

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat40.2of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factREPORTED

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

Independent primary confirmation of active exploitation would materially change this assessment.

AI analysis history (0)
    Technical severityUNKNOWNCVSS unknown · technical context
    Public exploitationREPORTEDGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSS0.99100th percentile · prediction
    Evidence confidence64%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      EPSS is 0.99; this is predictive context, not exploitation evidence.

    2. 02

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    No material changes are recorded for this subject.

    03

    Claim provenance

    Evidence and source independence

    1publications detected
    1underlying evidence chains

    0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
    60%claim confidence
    UNKNOWNreport:596ab81c2b7bd7bac499b413c11aec2aef15bc7eda9b3339f8d1f7ef4a4369dfACTIVE
    Evidence
    Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
    64%claim confidence
    UNKNOWNreport:596ab81c2b7bd7bac499b413c11aec2aef15bc7eda9b3339f8d1f7ef4a4369dfACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 06:5808 Aug
      EXPLOITATION REPORTED

      Exploitation Reported

      The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

    2. 06:5808 Aug
      ZERO DAY

      Zero Day

      The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

    05

    Original publications

    Source record

    Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

    Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

    CVE-2023-38646
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score40.2vtp-threat-v1-public
    Public exploitation12 / 30
    EPSS prediction19.74 / 20
    Exploit availability2.5 / 15
    Source independence0 / 15
    Intelligence recency6 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    Unknown · UNKNOWN
    Vector
    Unknown
    CWE
    Unknown
    CPE records
    0
    Deterministic history records
    2
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.