PT-2023-27343 · Pexip · Pexip Vmr

Published

2023-12-25

·

Updated

2023-12-29

·

CVE-2023-40236

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pexip VMR self-service portal versions prior to 3
Description The issue allows authentication bypass due to the use of the same SSH host key across different customers' installations.
Recommendations For versions prior to 3, update to version 3 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-40236

Affected Products

Pexip Vmr