CVE-2026-2103
Use of Hard-Coded Cryptographic Key for Password Storage
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.1EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
06 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Infor · SyteLine ERP¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →