Use of Hard-Coded Credentials
CVE-2023-40463

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
4 December 2023

What is CVE-2023-40463?

In certain configurations of ALEOS 4.16 and earlier, when debugging mode is enabled by an authenticated user with administrative privileges, the system improperly stores the SHA512 hash of the common root password. This information is saved in a directory that can be accessed by any user with root privileges or equivalent access rights, posing a significant risk of unauthorized password retrieval and potential system compromise.

Affected Version(s)

ALEOS 4.10 <= 4.16

ALEOS 0 <= 4.9.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.