CVE-2023-6451

HIGH

AlayaCare's Procura Portal <9.0.1.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

References (1)

Core 1

Scores

CVSS v3 8.6
EPSS 0.0053
EPSS Percentile 40.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1394 CWE-287
Status published
Products (1)
alayacare/procura < 9.0.1.2
Published Feb 16, 2024
Tracked Since Feb 18, 2026