Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://writeback4t.com | product |
https://www.xpand-it.com | product |
https://balwurk.com | not applicable |
https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/ | third party advisory |