AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-2158

CRITICAL · CVSS 9.8 EPSS 0.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-04-27 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.

CVE
CVE-2023-2158
Severity
CRITICAL
CVSS
9.8
EPSS
0.62%

Original NVD Description

Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who creates this token can supply it to a separate Code Dx system, provided they know the username they want to impersonate, and impersonate the user.  Score 6.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C

Related CVEs

Other vulnerabilities affecting the same vendor(s)