ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-52076 ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.
Fixes

Solution

ISOS firmwares from version 2.01 force the user to change the default credentials during the first login. For ISOS fimwares up to version 2.00, the default credentials must be changed by the user as documented in the « Initial staging » and « User access » chapters.


Workaround

No workaround given by the vendor.

History

Thu, 10 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2025-04-10T20:31:03.789Z

Reserved: 2022-12-28T09:17:05.953Z

Link: CVE-2022-4780

cve-icon Vulnrichment

Updated: 2024-08-03T01:48:40.472Z

cve-icon NVD

Status : Modified

Published: 2022-12-29T00:15:09.657

Modified: 2024-11-21T07:35:55.720

Link: CVE-2022-4780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.