CVE-2023-28124

Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:desktop:*:*:*:*:*:windows:*:*

History

01 May 2023, 20:26

Type Values Removed Values Added
References (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4 - (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:ui:desktop:*:*:*:*:*:windows:*:*
CWE CWE-326

20 Apr 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-19 20:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-28124

Mitre link : CVE-2023-28124

CVE.ORG link : CVE-2023-28124


JSON object : View

Products Affected

ui

  • desktop
CWE
CWE-326

Inadequate Encryption Strength