CVE-2022-1400

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
17/08/2022
Last modified:
18/08/2022

Description

Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:device42:cmdb:*:*:*:*:*:*:*:* 18.01.00 (excluding)