CVE Database
/

CVE-2023-42419

Back to search

CVE-2023-42419

Published: Mar 5, 2024

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

3.8

LOW

Description

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.

VendorProductVersions

Cybellum

Maintenance Server

affected
2.15.5 - <= 2.27
unaffected
1.*
unaffected
2.0 - <= 2.19
unaffected
2.28 - <= or above

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

High

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now