Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjwc-g6g3-rhhx

Опубликовано: 31 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

EPSS

Процентиль: 7%
0.00176
Низкий

8.1 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
nvd
9 дней назад

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

EPSS

Процентиль: 7%
0.00176
Низкий

8.1 High

CVSS3

Дефекты

CWE-798