go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Smartsoft SmartBPM.NET - Use of Hard-Coded Credentials - 1

TVN ID TVN-202307004
CVE ID CVE-2023-37286
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SmartBPM.NET: 6.7
Description SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Solution Contact SmartBPM.NET support team
Credit Alan Chung (DEVCORE)
Public Date 2023-09-19
Top