S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-32077 Scanner

CVE-2023-32077 Scanner - Hard-Coded Secret Key vulnerability in Netmaker

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-32077
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
netmakerby gravitl
< 0.17.1
Updated Aug 22, 2026View on NVD →
Detail

Netmaker is a tool developed by Gravitl that facilitates the creation and management of WireGuard-based networks. It is widely used by organizations seeking efficient and secure network connectivity solutions. Its functionality allows seamless integration of secure network connections across various platforms and devices. Companies and IT professionals leverage Netmaker to enhance their network infrastructure by establishing VPNs with minimal configuration. This tool supports cross-platform operability, making it suitable for diverse networking environments. As a result, it has gained traction among enterprises looking to streamline their network management while ensuring security.

The vulnerability in question involves the usage of a hardcoded DNS secret key within Netmaker versions prior to 0.17.1 and 0.18.6. Hardcoded credentials pose a significant security risk as they can be exploited by unauthorized users to access sensitive information or services. In this case, the hardcoded DNS key potentially allows unauthenticated interaction with DNS API endpoints, highlighting a crucial flaw in network security. Such vulnerabilities are critical since they can lead to unauthorized access without the need for any prior privileges or user authentication. This issue emphasizes the importance of secure credential management within software applications to prevent exploitation.

Technically, the vulnerability is detected through a GET request to the "/api/dns" endpoint of a Netmaker instance. The request uses a hardcoded secret key in the Authorization header, which, if not changed from its default value, could indicate potential security exposure. The typical symptoms of this vulnerability are visible when specific JSON elements such as "address," "network," and "name" are present in the response body, with a successful verification marked by a status code of 200. Such oversight in credential management reflects a configuration oversight, urging developers to implement secure handling for sensitive keys and parameters.

If exploited, this vulnerability could allow attackers to manipulate DNS settings, potentially redirecting traffic or conducting man-in-the-middle attacks. The misuse of hardcoded keys might also lead to unauthorized data access or service disruptions. In more severe cases, attackers could exploit this flaw to introduce malicious DNS records, severely compromising network security. Businesses relying on such configurations can find themselves vulnerable to data breaches and operational failures, underlining the necessity for robust cybersecurity practices. Maintaining updated software versions and proper credential management can mitigate these risks.

REFERENCES

Solution Advice
  • Update Netmaker to the latest version, which has addressed this vulnerability.
  • Ensure that all default credentials and secret keys are replaced with secure, unique values upon installation.
  • Implement regular audits of configuration files and API endpoints to detect and rectify any hardcoded credentials.
  • Incorporate automated tools to monitor and alert the presence of hardcoded sensitive information in the codebase.
  • Adopt a secure software development lifecycle to ensure credentials are handled securely across all stages of development.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.