Executive brief
MeshCentral is a web-based remote monitoring and management platform used to remotely access and control devices over networks. The application uses a broken or risky cryptographic algorithm, which weakens the security of encrypted communications and sensitive data protection. An attacker with network access could potentially decrypt or compromise encrypted data in transit or at rest.
Technical details
MeshCentral 1.1.16 uses a cryptographic algorithm that is considered broken or insufficient for secure operations (CWE-327). The vulnerability allows an attacker with network access to intercept and decrypt communications or bypass cryptographic protections without authentication requirements. The root cause stems from reliance on weak or deprecated cryptographic algorithms rather than secure modern alternatives. An attacker can achieve confidentiality breaches by decrypting sensitive data, though integrity and availability are not directly impacted. Patches addressing this issue are available in newer versions of MeshCentral beyond 1.1.16.
Affected products
- Ylianst MeshCentral 1.1.16 and earlier
Timeline
- 2024-02-02: disclosed
- 2024-02-02: advisory: GHSA-v269-rrr6-cx6r published