Back

HIGH

Use of hardcoded certificate and private key

Published Dec 4, 2023

Description

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded

SSL certificate and private key. An attacker with access to these items

could potentially perform a man in the middle attack between the

ACEManager client and ACEManager server.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SWI
Published Dec 4, 2023
Updated Feb 25, 2026
Reserved Aug 14, 2023
CISA Vulnrichment
Updated Dec 23, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SWI
Published Dec 4, 2023
Updated Feb 25, 2026
Exploited since n/a
EUVD-2023-45035