High severity8.6NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2023-37291
CVE-2023-37291
Description
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data.
This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 3.0.8 - 6.2.0
- Galaxy Software Services/Vitals ESPv5Range: 3.0.8
- cpe:2.3:a:gss:vitals_enterprise_social_platform:*:*:*:*:*:*:*:*Range: >=3.0.8,<=6.2.0
Patches
Vulnerability mechanics
References
1- www.twcert.org.tw/tw/cp-132-7224-4fe1f-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.