Use of hardcoded certificate and private key
CVE-2023-40464
6.8MEDIUM
What is CVE-2023-40464?
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and private key. An attacker with access to these items
could potentially perform a man in the middle attack between the
ACEManager client and ACEManager server.
Affected Version(s)
ALEOS 4.10 <= 4.16
ALEOS 0 <= 4.9.8