Security Advisory

CVE-2023-37286

9.8
CRITICAL

Vulnerability Description

SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Published Date July 10, 2023
Official Source NIST NVD Advisory