CVE-2023-47315
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 22, 2023
Updated: Nov 30, 2023
CWE ID 798
Summary
CVE-2023-47315: The Headwind MDM Web panel version 5.22.1 contains a critical vulnerability. A hard-coded JSON Web Token (JWT) secret, publicly available in the source code on GitHub, puts the application at risk. This secret is responsible for signing the panel's JWT tokens as well as verifying incoming user tokens. The incorrect access control arising from this hard-coded secret allows unauthorized users to gain privileged access to the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- HMDM