Junglewise Threat Intelligence

CVE-2023-51838: Ylianst MeshCentral weak cryptographic algorithm

CVE-2023-51838 · Severity: low · CVSS 3.1 · Published 2024-02-02

Technologies: Ylianst MeshCentral. Vendors: Ylianst.

Executive brief

MeshCentral is a web-based remote monitoring and management platform used to remotely access and control devices over networks. The application uses a broken or risky cryptographic algorithm, which weakens the security of encrypted communications and sensitive data protection. An attacker with network access could potentially decrypt or compromise encrypted data in transit or at rest.

Technical details

MeshCentral 1.1.16 uses a cryptographic algorithm that is considered broken or insufficient for secure operations (CWE-327). The vulnerability allows an attacker with network access to intercept and decrypt communications or bypass cryptographic protections without authentication requirements. The root cause stems from reliance on weak or deprecated cryptographic algorithms rather than secure modern alternatives. An attacker can achieve confidentiality breaches by decrypting sensitive data, though integrity and availability are not directly impacted. Patches addressing this issue are available in newer versions of MeshCentral beyond 1.1.16.

Affected products

  • Ylianst MeshCentral 1.1.16 and earlier

Timeline

  • 2024-02-02: disclosed
  • 2024-02-02: advisory: GHSA-v269-rrr6-cx6r published

References

Related threats