← back
CVE-2023-43617

CVE-2023-43617

EPSS 0.6%CWE-200
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Sep 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.
Affected products
n/a · n/a