Description
Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.
The issue was resolved in version 2.28.
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.
The issue was resolved in version 2.28.
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
No analysis available yet.
Remediation
Vendor Solution
Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27 -> Upgrade to version 2.28 or above All other versions/distributions -> Unaffected
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46871 | Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected. |
References
| Link | Providers |
|---|---|
| https://cybellum.com/ |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: Cybellum
Published:
Updated: 2024-08-02T19:16:51.043Z
Reserved: 2023-09-08T04:33:08.334Z
Link: CVE-2023-42419
Updated: 2024-05-23T19:01:16.217Z
Status : Deferred
Published: 2024-03-05T06:15:52.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-42419
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD