Weak password requirements in SEPCOS Single Package - CVE-2022-1668
Published: June 27, 2022
Vulnerability identifier: #VU64687
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1668
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to perform brute-force attack and guess the password.
The vulnerability exists due to weak password requirements. An attacker can obtain OS superuser privileges over the open TCP port for SSH.
Affected software
SEPCOS Single Package
How to mitigate CVE-2022-1668
Install updates from vendor's website.
SEPCOS Single Package - addressed in versions 1.23.21, 1.24.8, 1.25.3