CVE-2023-27169

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xpand-it:write-back_manager:2.3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:52

Type Values Removed Values Added
References () https://balwurk.com - Not Applicable () https://balwurk.com - Not Applicable
References () https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/ - Third Party Advisory () https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/ - Third Party Advisory
References () https://writeback4t.com - Product () https://writeback4t.com - Product
References () https://www.xpand-it.com - Product () https://www.xpand-it.com - Product

Information

Published : 2023-09-12 12:15

Updated : 2024-11-21 07:52


NVD link : CVE-2023-27169

Mitre link : CVE-2023-27169

CVE.ORG link : CVE-2023-27169


JSON object : View

Products Affected

xpand-it

  • write-back_manager
CWE
CWE-798

Use of Hard-coded Credentials