Use of Hard-Coded Credentials
CVE-2023-40463
8.1HIGH
What is CVE-2023-40463?
In certain configurations of ALEOS 4.16 and earlier, when debugging mode is enabled by an authenticated user with administrative privileges, the system improperly stores the SHA512 hash of the common root password. This information is saved in a directory that can be accessed by any user with root privileges or equivalent access rights, posing a significant risk of unauthorized password retrieval and potential system compromise.
Affected Version(s)
ALEOS 4.10 <= 4.16
ALEOS 0 <= 4.9.8