FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
History

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Fydeos
Fydeos fydeos
Fydeos openfyde
Weaknesses CWE-259
CPEs cpe:2.3:o:fydeos:fydeos:*:*:*:*:*:*:*:*
cpe:2.3:o:fydeos:openfyde:*:*:*:*:*:*:*:*
Vendors & Products Fydeos
Fydeos fydeos
Fydeos openfyde
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-09T00:00:00

Updated: 2024-10-10T15:37:49.835Z

Reserved: 2024-02-12T00:00:00

Link: CVE-2024-25825

cve-icon Vulnrichment

Updated: 2024-10-10T15:03:51.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-09T16:15:04.277

Modified: 2024-10-11T21:36:24.583

Link: CVE-2024-25825

cve-icon Redhat

No data.