Description
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Published: 2026-09-15
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a hard‑coded cryptographic key used by the deployer‑ng Update Controller in Wärtsilä FOS‑Onboard. An attacker who can influence the Update Controller code or data could exploit the fixed key to decode protected traffic, sign certificates, or fabricate control messages, effectively bypassing encryption and gaining unauthorized access to the system. The flaw represents a classic key‑management weakness, classified as CWE‑321, and because the key is immutable, any compromise allows long‑term persistence and broad impact on all encrypted communications. The high CVSS score of 9.5 reflects the combination of confidentiality and integrity loss that would result from successful exploitation.

Affected Systems

The issue affects Wärtsilä FOS‑Onboard, specifically the deployer‑ng Update Controller component. No precise version numbers are supplied in the available data; therefore the vulnerability may exist in any deployed instance of FOS‑Onboard that contains the referenced component. System administrators should check all installed FOS‑Onboard deployments for the presence of the hard‑coded key regardless of version.

Risk and Exploitability

The CVSS score of 9.5 indicates an extremely severe weakness that could lead to full system compromise. However, the EPSS score is less than 1%, suggesting that, at present, the probability of real‑world exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog, so no confirmed attacks are known. Attackers would most likely target the component via network interfaces or administrative access to inject malicious update packages, assuming they can reach the Update Controller. Unless the product is installed according to Wärtsilä’s recommended configuration – which the vendor says mitigates the risk – the fixed key remains exploitable.

Generated by OpenCVE AI on September 16, 2026 at 21:24 UTC.

Remediation

Vendor Solution

Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä:  https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact


OpenCVE Recommended Actions

  • Obtain the latest security patch from Wärtsila and apply it to all FOS‑Onboard installations
  • Follow the vendor’s installation guidance to ensure the product is deployed as recommended, which includes disabling any legacy update paths that may expose the hard‑coded key
  • Implement network segmentation and firewall rules to isolate the Update Controller, limiting exposure to potential attackers

Generated by OpenCVE AI on September 16, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Title Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T18:05:16.902Z

Reserved: 2026-09-08T16:53:35.715Z

Link: CVE-2026-78225

cve-icon Vulnrichment

Updated: 2026-09-16T18:05:12.653Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T22:17:02.870

Modified: 2026-09-16T19:30:28.743

Link: CVE-2026-78225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:30:06Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key