SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41193 | SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service. |
Fixes
Solution
Contact SmartSoft.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7221-438c6-1.html |
|
History
Tue, 12 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-11-12T19:28:26.124Z
Reserved: 2023-06-30T00:00:00.000Z
Link: CVE-2023-37286
Updated: 2024-08-02T17:09:34.186Z
Status : Modified
Published: 2023-07-10T02:15:45.237
Modified: 2024-11-21T08:11:24.040
Link: CVE-2023-37286
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD