Impact
The vulnerability is a hard‑coded cryptographic key used by the deployer‑ng Update Controller in Wärtsilä FOS‑Onboard. An attacker who can influence the Update Controller code or data could exploit the fixed key to decode protected traffic, sign certificates, or fabricate control messages, effectively bypassing encryption and gaining unauthorized access to the system. The flaw represents a classic key‑management weakness, classified as CWE‑321, and because the key is immutable, any compromise allows long‑term persistence and broad impact on all encrypted communications. The high CVSS score of 9.5 reflects the combination of confidentiality and integrity loss that would result from successful exploitation.
Affected Systems
The issue affects Wärtsilä FOS‑Onboard, specifically the deployer‑ng Update Controller component. No precise version numbers are supplied in the available data; therefore the vulnerability may exist in any deployed instance of FOS‑Onboard that contains the referenced component. System administrators should check all installed FOS‑Onboard deployments for the presence of the hard‑coded key regardless of version.
Risk and Exploitability
The CVSS score of 9.5 indicates an extremely severe weakness that could lead to full system compromise. However, the EPSS score is less than 1%, suggesting that, at present, the probability of real‑world exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog, so no confirmed attacks are known. Attackers would most likely target the component via network interfaces or administrative access to inject malicious update packages, assuming they can reach the Update Controller. Unless the product is installed according to Wärtsilä’s recommended configuration – which the vendor says mitigates the risk – the fixed key remains exploitable.
OpenCVE Enrichment