Hard-coded credentials pose security risk in new firmware update
CVE-2024-28146

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
12 December 2024

Badges

👾 Exploit Exists

What is CVE-2024-28146?

This vulnerability arises from the use of hard-coded credentials within the ImageAccess firmware, which are utilized to manage configuration file encryption during backups and to decrypt firmware updates. These credentials also facilitate unauthorized direct access to the database server of affected devices, significantly compromising system integrity and security. It is crucial for users to review their firmware versions and apply necessary updates to mitigate this risk.

Affected Version(s)

Scan2Net 0

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Hirschberger (SEC Consult Vulnerability Lab)
Tobias Niemann (SEC Consult Vulnerability Lab)
.