PT-2022-4179 · Device42 · Device42 Cmdb

Published

2022-08-12

·

Updated

2022-08-18

·

CVE-2022-1400

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Device42 CMDB versions prior to 18.01.00
Description The issue is related to the use of a hard-coded cryptographic key in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance. This allows an attacker to leak session IDs and elevate privileges. The exploitation of this issue can enable a remote attacker to obtain the encryption key.
Recommendations For Device42 CMDB versions prior to 18.01.00, update to version 18.01.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebReportsApi.dll to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-05026
CVE-2022-1400

Affected Products

Device42 Cmdb