CVE-2023-42419

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2024
Last modified:
05/03/2024

Description

Maintenance Server, in Cybellum&amp;#39;s QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.<br /> <br /> <br /> An attacker with administrative privileges &amp; access to the air-gapped server could potentially use this key to run commands on the server.<br /> The issue was resolved in version 2.28.<br /> Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.<br /> <br />

References to Advisories, Solutions, and Tools