← back
CVE-2023-32090criticalCWE-1393

CVE-2023-32090

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In short

Pega platform versions 6.1 to 7.3.1 may come with default credentials that attackers can use to gain unauthorized access. This is critical because anyone on the internet could potentially log in without permission.

Technical detail

Default credentials in Pega platform versions 6.1–7.3.1 enable unauthenticated or low-privilege remote attackers to gain administrative access without valid credentials. The vulnerability requires no user interaction and affects systems exposed to the network, resulting in complete system compromise.

Summary generated and translated by AI from the official description.
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H