CVE-2023-51638

CRITICAL

Allegra < 7.5.1 - Unauthenticated Authentication Bypass via Hard-coded Database Credentials

Title source: llm
STIX 2.1

Description

Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of a database. The issue results from the use of a hardcoded password. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22360.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0130
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
alltena/allegra < 7.5.1
Published Nov 22, 2024
Tracked Since Feb 18, 2026