Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc6c-v4m2-858f

Опубликовано: 19 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

EPSS

Процентиль: 24%
0.00084
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database with superuser privileges, create administrative users for the web interface, and potentially escalate privileges further.

EPSS

Процентиль: 24%
0.00084
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321