CVE-2023-0391

MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mgt-commerce:cloudpanel:*:*:*:*:*:*:*:*

History

27 Mar 2023, 22:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
References (MISC) https://www.rapid7.com/blog/post/2023/03/21/cve-2023-0391-mgt-commerce-cloudpanel-shared-certificate-vulnerability-and-weak-installation-procedures/ - (MISC) https://www.rapid7.com/blog/post/2023/03/21/cve-2023-0391-mgt-commerce-cloudpanel-shared-certificate-vulnerability-and-weak-installation-procedures/ - Exploit, Third Party Advisory
References (MISC) https://www.bleepingcomputer.com/news/security/cloudpanel-installations-use-the-same-ssl-certificate-private-key/ - (MISC) https://www.bleepingcomputer.com/news/security/cloudpanel-installations-use-the-same-ssl-certificate-private-key/ - Exploit, Press/Media Coverage, Third Party Advisory
CWE CWE-798
CPE cpe:2.3:a:mgt-commerce:cloudpanel:*:*:*:*:*:*:*:*
First Time Mgt-commerce cloudpanel
Mgt-commerce

23 Mar 2023, 19:15

Type Values Removed Values Added
References
  • (MISC) https://www.bleepingcomputer.com/news/security/cloudpanel-installations-use-the-same-ssl-certificate-private-key/ -

21 Mar 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-21 20:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-0391

Mitre link : CVE-2023-0391

CVE.ORG link : CVE-2023-0391


JSON object : View

Products Affected

mgt-commerce

  • cloudpanel
CWE
CWE-798

Use of Hard-coded Credentials

CWE-321

Use of Hard-coded Cryptographic Key