PT-2022-4179 · Device42 · Device42 Cmdb
Published
2022-08-12
·
Updated
2022-08-18
·
CVE-2022-1400
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Device42 CMDB versions prior to 18.01.00
Description
The issue is related to the use of a hard-coded cryptographic key in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance. This allows an attacker to leak session IDs and elevate privileges. The exploitation of this issue can enable a remote attacker to obtain the encryption key.
Recommendations
For Device42 CMDB versions prior to 18.01.00, update to version 18.01.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebReportsApi.dll to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Device42 Cmdb