ZeroHour

CVE-2023-0391

PoC ×2
CVSS 3.1
8.1 high
EPSS
<1%p47
Published
()
Modified
Description

MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1.

Vendors
mgt-commerce
Products
cloudpanel
Weakness
CWE-321, CWE-798
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.