Security Advisory

CVE-2023-37286

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-10 00:00:00
Last updated 2024-11-12 19:28:26
Assigner twcert
State PUBLISHED

Description

SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.