Use of hardcoded certificate and private key
CVE-2023-40464

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
4 December 2023

What is CVE-2023-40464?

Several versions of ALEOS, particularly starting from ALEOS 4.16.0, have been discovered to utilize a hardcoded SSL certificate and private key. This vulnerability exposes systems to potential man-in-the-middle attacks, enabling malicious actors to intercept traffic between the ACEManager client and the ACEManager server. Organizations using affected versions of ALEOS should evaluate their security posture and update their systems to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ALEOS 4.10 <= 4.16

ALEOS 0 <= 4.9.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.