CVE-2023-0391
MGT-COMMERCE CloudPanel Shared Certificate
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.1EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
21 mar 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
MGT-COMMERCE · CloudPanelQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →