Impact
A vulnerability exists in SxDevOps version 1.0 and 1.1 where the function ensure_default_superuser contains hard‑coded credentials. The flaw is a credential compromise weakness that can allow an attacker to obtain privileged access, potentially gaining full control of the system.
Affected Systems
Vendors and affected products include aiyiyi121 SxDevOps versions 1.0 and 1.1. The vulnerability is present in the rbac/services.py file, and the provider has released a patch with commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The description states that remote attackers can exploit this flaw, so the attack vector is likely remote. Because the flaw involves hard‑coded credentials, a successful exploitation would lead to privilege escalation.
OpenCVE Enrichment