Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58688 | Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms. |
Fixes
Solution
Generate new machine keys in the application's web.config file immediately.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alayacare
Alayacare procura |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:alayacare:procura:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alayacare
Alayacare procura |
Status: PUBLISHED
Assigner: TML
Published:
Updated: 2024-08-02T08:28:21.849Z
Reserved: 2023-11-30T22:06:55.677Z
Link: CVE-2023-6451
Updated: 2024-08-02T08:28:21.849Z
Status : Analyzed
Published: 2024-02-16T04:15:08.090
Modified: 2025-01-09T14:56:51.713
Link: CVE-2023-6451
No data.
OpenCVE Enrichment
No data.
EUVD