CVE-2023-40464: Use of hardcoded certificate and private key
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and private key. An attacker with access to these items
could potentially perform a man in the middle attack between the
ACEManager client and ACEManager server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40464?
CVE-2023-40464 is a vulnerability that allows an attacker to perform a man-in-the-middle attack by using a hardcoded SSL certificate and private key in ALEOS versions up to 4.16.0.
Which software versions are affected by CVE-2023-40464?
ALEOS versions up to 4.16.0 are affected by CVE-2023-40464.
What is the severity of CVE-2023-40464?
CVE-2023-40464 has a severity rating of 8.1 (high).
How can an attacker exploit CVE-2023-40464?
An attacker with access to the hardcoded SSL certificate and private key could perform a man-in-the-middle attack between the ACEManager client and ACEManager server.
How can I mitigate the risk of CVE-2023-40464?
To mitigate the risk of CVE-2023-40464, it is recommended to update ALEOS to a version that does not use the hardcoded SSL certificate and private key, or follow the recommendations provided by the vendor.