Hard-coded credentials pose security risk in new firmware update
CVE-2024-28146
8.4HIGH
Key Information:
- Vendor
Image Access Gmbh
- Status
- Vendor
- CVE Published:
- 12 December 2024
Badges
👾 Exploit Exists
What is CVE-2024-28146?
This vulnerability arises from the use of hard-coded credentials within the ImageAccess firmware, which are utilized to manage configuration file encryption during backups and to decrypt firmware updates. These credentials also facilitate unauthorized direct access to the database server of affected devices, significantly compromising system integrity and security. It is crucial for users to review their firmware versions and apply necessary updates to mitigate this risk.
Affected Version(s)
Scan2Net 0
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Daniel Hirschberger (SEC Consult Vulnerability Lab)
Tobias Niemann (SEC Consult Vulnerability Lab)
