In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://docs.pexip.com/admin/security_bulletins.htm | vendor advisory |