Hardcoded encryption key IV in Exago WebReportsApi.dll
Vulnerability Description
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1400
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Ștefania POPESCU - Team Lead, Security @ Bitdefender
- Ionuț LALU - Security Engineer @ Bitdefender
- Cristian BUZA - Security Engineer @ Bitdefender
- Alexandru LAZĂR - Security Researcher @ Bitdefender
Affected Vendor
Device42
View all reports →