Vulnerabilities > CVE-2023-37291 - Use of Hard-coded Cryptographic Key vulnerability in GSS Vitals Enterprise Social Platform 3.0.8/6.2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |