Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.
The issue was resolved in version 2.28.
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cybellum.com/ |
|
History
No history.
Status: PUBLISHED
Assigner: Cybellum
Published:
Updated: 2024-08-02T19:16:51.043Z
Reserved: 2023-09-08T04:33:08.334Z
Link: CVE-2023-42419
Updated: 2024-05-23T19:01:16.217Z
Status : Deferred
Published: 2024-03-05T06:15:52.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-42419
No data.
OpenCVE Enrichment
No data.