CVE-2023-41137

Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
AppCheckCNA
8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
appsanywhereappsanywhere_client
1.4.0
appsanywhereappsanywhere_client
1.4.1
appsanywhereappsanywhere_client
1.5.1
appsanywhereappsanywhere_client
1.6.0
appsanywhereappsanywhere_client
2.0.0
appsanywhereappsanywhere_client
1.4.0
appsanywhereappsanywhere_client
1.4.1
appsanywhereappsanywhere_client
1.5.1
appsanywhereappsanywhere_client
1.5.2
appsanywhereappsanywhere_client
1.6.0
appsanywhereappsanywhere_client
2.0.0
𝑥
= Vulnerable software versions