CVE Vulnerabilities

CVE-2023-6451

Use of Default Cryptographic Key

Published: Feb 16, 2024 | Modified: Jan 09, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Publicly known cryptographic machine key in AlayaCares Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the applications authentication mechanisms.

Weakness

The product uses a default cryptographic key for potentially critical functionality.

Affected Software

NameVendorStart VersionEnd Version
ProcuraAlayacare*9.0.1.2 (excluding)

Potential Mitigations

References