Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6xg-wr2p-xrj3

Опубликовано: 26 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

EPSS

Процентиль: 40%
0.00498
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-259

Связанные уязвимости

CVSS3: 9.8
nvd
2 месяца назад

Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

EPSS

Процентиль: 40%
0.00498
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-259