First published: Wed Apr 19 2023(Updated: )
Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Desktop | <0.62.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28124 is a vulnerability that involves improper usage of symmetric encryption in UI Desktop for Windows.
The severity of CVE-2023-28124 is medium, with a severity value of 5.5.
Users with access to UI Desktop configuration files can decrypt their content due to the improper usage of symmetric encryption.
To fix CVE-2023-28124, update UI Desktop for Windows to version 0.62.3 or later.
You can find more information about CVE-2023-28124 in the Security Advisory Bulletin on the UI community website.