CVE-2023-0391
Summary
| CVE | CVE-2023-0391 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-21 20:15:00 UTC |
| Updated | 2023-03-27 22:21:00 UTC |
| Description | MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been addressed in version 2.2.1. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mgt-commerce | Cloudpanel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CloudPanel installations use the same SSL certificate private key | MISC | www.bleepingcomputer.com | |
| CVE-2023-0391: CloudPanel Shared Certificate Vulnerability | Rapid7 Blog | MISC | www.rapid7.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.