Arbitrary Code Execution Vulnerability in IGEL Universal Management Suite by IGEL Technologies
CVE-2022-25806
8.8HIGH
What is CVE-2022-25806?
A vulnerability exists in IGEL Universal Management Suite (UMS) 6.07.100 due to the presence of a hardcoded DES key within the PrefDBCredentials class. This flaw permits an attacker, who has obtained encrypted superuser credentials, to decrypt these credentials using a static 8-byte DES key, potentially allowing unauthorized access and exploitation of the management suite.
