CVE-2023-40236: Medium severity pexip virtual meeting rooms vulnerability
Published Dec 25, 2023
·Updated
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
Affected Software
1 affected component
Pexip Virtual Meeting Rooms<3.0
Event History
Dec 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40236?
CVE-2023-40236 has been classified with a high severity level due to the potential for authentication bypass.
2
How do I fix CVE-2023-40236?
To mitigate CVE-2023-40236, upgrade to Pexip VMR version 3.0 or later.
3
Who is affected by CVE-2023-40236?
CVE-2023-40236 affects all customers using Pexip VMR self-service portal versions before 3.0.
4
What are the risks associated with CVE-2023-40236?
The risks of CVE-2023-40236 include unauthorized access and possible exploitation of the system.
5
Is there a known exploit for CVE-2023-40236?
As of now, there are no publicly known exploits specifically targeting CVE-2023-40236.