CVE-2023-41137

EUVD-2023-45656
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
AppCheckCNA
8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
appsanywhereappsanywhere_client
1.4.0
appsanywhereappsanywhere_client
1.4.1
appsanywhereappsanywhere_client
1.5.1
appsanywhereappsanywhere_client
1.6.0
appsanywhereappsanywhere_client
2.0.0
appsanywhereappsanywhere_client
1.4.0
appsanywhereappsanywhere_client
1.4.1
appsanywhereappsanywhere_client
1.5.1
appsanywhereappsanywhere_client
1.5.2
appsanywhereappsanywhere_client
1.6.0
appsanywhereappsanywhere_client
2.0.0
𝑥
= Vulnerable software versions