Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9v9-64wf-34gh

Опубликовано: 26 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.8

Описание

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface.

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface.

EPSS

Процентиль: 21%
0.00068
Низкий

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
ubuntu
8 месяцев назад

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

CVSS3: 8.8
nvd
8 месяцев назад

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

EPSS

Процентиль: 21%
0.00068
Низкий

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-798