Use of hardcoded certificate and private key
CVE-2023-40464
8.1HIGH
What is CVE-2023-40464?
Several versions of ALEOS, particularly starting from ALEOS 4.16.0, have been discovered to utilize a hardcoded SSL certificate and private key. This vulnerability exposes systems to potential man-in-the-middle attacks, enabling malicious actors to intercept traffic between the ACEManager client and the ACEManager server. Organizations using affected versions of ALEOS should evaluate their security posture and update their systems to mitigate these risks.
Affected Version(s)
ALEOS 4.10 <= 4.16
ALEOS 0 <= 4.9.8
