In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
                
            References
                    | Link | Resource | 
|---|---|
| https://docs.pexip.com/admin/security_bulletins.htm | Vendor Advisory | 
| https://docs.pexip.com/admin/security_bulletins.htm | Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:19
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://docs.pexip.com/admin/security_bulletins.htm - Vendor Advisory | 
29 Dec 2023, 18:39
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.3  | 
| CPE | cpe:2.3:a:pexip:virtual_meeting_rooms:*:*:*:*:*:*:*:* | |
| References | () https://docs.pexip.com/admin/security_bulletins.htm - Vendor Advisory | |
| CWE | CWE-798 | |
| First Time | 
        
        Pexip virtual Meeting Rooms
         Pexip  | 
25 Dec 2023, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-12-25 06:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-40236
Mitre link : CVE-2023-40236
CVE.ORG link : CVE-2023-40236
JSON object : View
Products Affected
                pexip
- virtual_meeting_rooms
 
CWE
                
                    
                        
                        CWE-798
                        
            Use of Hard-coded Credentials
