CVE-2023-28870: Ncp-E Secure Enterprise Client

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.

Affected products

  • Ncp-E Secure Enterprise Client: before 12.22 (fixed in 12.22)

Published 2023-12-09. Last modified 2026-06-17.