desknet's NEO Hard-Coded Cryptographic Key Vulnerability Allowing Malicious AppSuite Application Creation

Vulnerability

A vulnerability exists in desknet's NEO versions 4.0R1.0 to 9.0R2.0, due to a hard-coded cryptographic key. This flaw enables an attacker to create malicious AppSuite applications. The issue affects users logged into desknet's NEO, particularly those who can input or register scripts, as the vulnerability could be exploited to execute arbitrary JavaScript in the user's web browser.

Impact

Exploitation of this vulnerability allows for the creation of malicious AppSuite applications, which could potentially be used to execute harmful actions within the AppSuite environment.

Remediation

Users are advised to update desknet's NEO to version 9.5 R1.0 or later. For those using the PostgreSQL or SQL Server versions, the update module can be downloaded and installed. Customers with a customized version or the Oracle version should contact NEOJAPAN for guidance.

Added: Oct 16, 2025, 10:18 AM
Updated: Oct 16, 2025, 3:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
4.9
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.