CVE-2023-27169

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xpand-it:write-back_manager:2.3.1:*:*:*:*:*:*:*

History

13 Sep 2023, 17:38

Type Values Removed Values Added
First Time Xpand-it
Xpand-it write-back Manager
CPE cpe:2.3:a:xpand-it:write-back_manager:2.3.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-798
References (MISC) https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/ - (MISC) https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/ - Third Party Advisory
References (MISC) https://balwurk.com - (MISC) https://balwurk.com - Not Applicable
References (MISC) https://www.xpand-it.com - (MISC) https://www.xpand-it.com - Product
References (MISC) https://writeback4t.com - (MISC) https://writeback4t.com - Product

12 Sep 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-12 12:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-27169

Mitre link : CVE-2023-27169

CVE.ORG link : CVE-2023-27169


JSON object : View

Products Affected

xpand-it

  • write-back_manager
CWE
CWE-798

Use of Hard-coded Credentials