Impact
Use of weak credentials—default or expected passwords—within mapp Audit permits attackers to authenticate without proper authorization. Successfully authenticating allows an attacker potentially to view, modify, or delete audit data, and if the audit component has elevated privileges, to pivot into other parts of the mapp Services environment. The vulnerability leverages the inherent weakness of password enforcement and is classified under CWE‑1391.
Affected Systems
The affected product is B&R Industrial Automation GmbH mapp Audit used in mapp Services, specifically all releases prior to version 6.8.0. No other vendor or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 7 indicates a high severity exploit. No EPSS score is published, so the precise likelihood of exploitation is undetermined, but the lack of a KEV listing suggests it has not yet been widely exploited publicly. The most likely attack vector is remote authentication through exposed service interfaces, where an attacker supplies weak or default credentials. If successful, the attacker gains unauthorized access with potentially full control of the audit service.
OpenCVE Enrichment