Weak password requirements in SEPCOS Single Package - CVE-2022-1668

 

Weak password requirements in SEPCOS Single Package - CVE-2022-1668

Published: June 27, 2022


Vulnerability identifier: #VU64687
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1668
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform brute-force attack and guess the password.

The vulnerability exists due to weak password requirements. An attacker can obtain OS superuser privileges over the open TCP port for SSH.


Affected software

SEPCOS Single Package

How to mitigate CVE-2022-1668

Install updates from vendor's website.

SEPCOS Single Package - addressed in versions 1.23.21, 1.24.8, 1.25.3

External References

Related Security Bulletins