We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-42419

Improper Management of Cryptographic Keys in the Maintenance Server in QCOW Air-Gapped Distribution (China Edition)



AssignerCybellum
Reserved2023-09-08
Published2024-03-05
Updated2024-08-02

Description

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.



LOW: 3.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

The vulnerability exploitation is limited by the need for administrative access & connection to internal air-gapped networks, reducing its potential impact

Product status

Default status
unaffected

2.15.5
affected

1.*
unaffected

2.0
unaffected

2.28
unaffected

Credits

Delikely finder

References

https://cybellum.com/

cve.org CVE-2023-42419

nvd.nist.gov CVE-2023-42419

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-42419

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.