Impact
SmartIT Desktop Manager contains hard‑coded credentials that unanuthenticated remote attackers can retrieve from the application or its source code. By extracting this password, an attacker can obtain the AES key used for secure communication, allowing decryption of traffic, impersonation of legitimate clients, or otherwise unauthorized access. The vulnerability reflects an authentication failure weakness (CWE‑284) and compromises the confidentiality and integrity of communications.
Affected Systems
Lightstar SmartIT Desktop Manager is affected. No specific version numbers are listed, so all installations using versions older than 11 could be vulnerable. The vendor recommends upgrading to SmartIT Desktop Manager 11 or later.
Risk and Exploitability
The flaw receives a CVSS score of 8.7, indicating high severity. EPSS data is not available, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is unauthenticated remote access, potentially via an exposed source file or insecure configuration that permits reading the hard‑coded password. Because the exploit does not require privileged access on the target, it could be carried out by a readily available attacker.
OpenCVE Enrichment