Vulnerabilities > CVE-2023-37291 - Use of Hard-coded Cryptographic Key vulnerability in GSS Vitals Enterprise Social Platform 3.0.8/6.2.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
gss
CWE-321
critical

Summary

Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.

Vulnerable Configurations

Part Description Count
Application
Gss
2

Common Weakness Enumeration (CWE)