CVE-2023-2158

CVE-2023-2158: Impersonation through User-Controlled Token

Vendor Synopsys
Product Code Dx
Weakness CWE-321
Published April 27, 2023
Last update January 31, 2025

CVSS base score

What the vulnerability does

01Description

Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who creates this token can supply it to a separate Code Dx system, provided they know the username they want to impersonate, and impersonate the user.  Score 6.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C

Key dates

02Disclosure timeline

April 27, 2023 CVE published
January 31, 2025 Record updated