Description
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data.



This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
Published: 2023-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Contact support from  Galaxy Software Services

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-41198 Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
History

Thu, 24 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Oct 2024 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798

Mon, 14 Oct 2024 03:45:00 +0000

Type Values Removed Values Added
Description Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0. Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
Weaknesses CWE-321

Subscriptions

Gss Vitals Enterprise Social Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-24T14:31:28.873Z

Reserved: 2023-06-30T02:08:23.931Z

Link: CVE-2023-37291

cve-icon Vulnrichment

Updated: 2024-08-02T17:09:34.184Z

cve-icon NVD

Status : Modified

Published: 2023-07-21T04:15:15.080

Modified: 2024-11-21T08:11:24.740

Link: CVE-2023-37291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses