Impact
The vulnerability is a fixed cryptographic server key embedded within the deployer‑ng Update Controller component of Wärtsilä FOS‑Onboard. This key can be used by an attacker to decrypt secured traffic, sign certificates, or forge control commands, thereby compromising the confidentiality and integrity of all data the Update Controller protects. The flaw is a key‑management weakness, classified as CWE‑321, and because the key is immutable, exploitation provides persistent backdoor access to the system’s control plane.
Affected Systems
The issue affects Wärtsilä FOS‑Onboard deployments that include the deployer‑ng Update Controller. No specific version numbers are indicated in the available data, so all instances of FOS‑Onboard that contain the affected component may be vulnerable until the vendor‑issued patch is applied. Administrators should verify that their installations meet Wärtsilä’s recommended configuration guidance.
Risk and Exploitability
The CVSS score of 9.5 indicates a high‑severity flaw, but the EPSS score of less than 1% suggests that, at present, exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed attacks yet. Based on the description, it is inferred that the attack vector would involve an attacker gaining network or administrative access to the Update Controller to inject malicious update packages or otherwise interact with the hard‑coded key, allowing decryption of traffic and creation of forged messages.
OpenCVE Enrichment