Impact
Datiphy Data Management Center versions 8.3.0 through 8.5.1 contain a flaw allowing the use of default administrator credentials. An attacker who can reach the web interface can log in as administrator when default credentials remain unchanged, thereby gaining full control over configuration, data, and potentially compromising all stored assets.
Affected Systems
The vulnerability affects Datiphy Inc.’s Data Management Center product, specifically releases from version 8.3.0 up to and including 8.5.1. No other versions or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, and the absence of an EPSS score means the exploitation probability is not quantified but could be significant given the wide user base of these versions. The attack can typically be carried out remotely over the internet by entering default credentials at the login page; thus the vector is inferred as remote network access. The vulnerability is not currently listed in CISA’s KEV catalog, but its high score warrants proactive remediation.
OpenCVE Enrichment