Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data.
This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-7224-4fe1f-1.html |
![]() ![]() |
History
Thu, 24 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Oct 2024 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-798 |
Mon, 14 Oct 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0. | Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0. |
Weaknesses | CWE-321 |

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-24T14:31:28.873Z
Reserved: 2023-06-30T02:08:23.931Z
Link: CVE-2023-37291

Updated: 2024-08-02T17:09:34.184Z

Status : Modified
Published: 2023-07-21T04:15:15.080
Modified: 2024-11-21T08:11:24.740
Link: CVE-2023-37291

No data.