CVE-2023-42419
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2024
Last modified:
05/03/2024
Description
Maintenance Server, in Cybellum&#39;s QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.<br />
<br />
<br />
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.<br />
The issue was resolved in version 2.28.<br />
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.<br />
<br />
Impact
Base Score 3.x
3.80
Severity 3.x
LOW