CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.0 are vulnerable due to a hardcoded default secret key in the standalone telemetry server configuration, which is used for hashing API keys. This flaw allows attackers with knowledge of the default key to predict or forge API key hashes, potentially compromising telemetry API authentication. Organizations using affected versions of OpenSSL should prioritize this vulnerability to safeguard their API security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
Related CVEs
Other vulnerabilities affecting the same vendor(s)