CVE-2023-27169
Low
No strong exploitation signal.
CVSS base
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS — probability of exploitation (30 days)
0.3%
25.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-798
Published 2023-09-12 · modified 2026-09-16
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | L | Low |
| Integrity | L | Low |
| Availability | N | None |
Timeline
- 2023-09-12 — Published (NVD)
- 2026-09-16 — Last modified (NVD)
Description
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Affected
References
- https://balwurk.com
- https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/
- https://ghostline.neocities.org/CVE-2023-27169/
- https://writeback4t.com
- https://www.xpand-it.com
- https://balwurk.com
- https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/
- https://writeback4t.com
- https://www.xpand-it.com