CVE-2023-27169
Executive Summary
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in its license configuration, producing predictable symmetric encryption keys. This flaw allows attackers to derive the key, potentially bypassing license validation and enabling unauthorized use or tampering. The vulnerability is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2023-09-12T12:15:07.580 - Last Modified: 2026-09-16T20:17:19.963
Original Description: Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
"Great acts are made up of small deeds."
— Lao Tzu
Source: NVD