CVE-2023-40300
published 2023-12-07CVE-2023-40300: NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.71%
48.7th percentile
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netscout | ngeniuspulse | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-iot vulnerabilities
osv·2025-12-04·CVSS 7.8
CVE-2025-40300 linux-iot vulnerabilities
linux-iot vulnerabilities
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- HSI subsystem;
- I3C subsystem;
- SMB network file system;
- Padata parallel execution mechanism;
- Timer subsystem;
- Networking core;
(CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-56664,
CVE-2025-21727, CVE-2025-3
OSV
linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
osv·2025-11-19·CVSS 7.8
CVE-2025-40300 linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- HSI subsystem;
- I3C subsystem;
- SMB network file system;
- Padata parallel execution mechanism;
- Timer subsystem;
- Networking core;
(CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-
GHSA
GHSA-q22m-mcvp-rxgv: NETSCOUT nGeniusPULSE 3
ghsa_unreviewed·2023-12-07
CVE-2023-40300 [CRITICAL] CWE-798 GHSA-q22m-mcvp-rxgv: NETSCOUT nGeniusPULSE 3
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-07
Published