Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.
The issue was resolved in version 2.28.
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server.
The issue was resolved in version 2.28.
Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46871 | Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected. |
Fixes
Solution
Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27 -> Upgrade to version 2.28 or above All other versions/distributions -> Unaffected
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cybellum.com/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Cybellum
Published:
Updated: 2024-08-02T19:16:51.043Z
Reserved: 2023-09-08T04:33:08.334Z
Link: CVE-2023-42419
Updated: 2024-05-23T19:01:16.217Z
Status : Deferred
Published: 2024-03-05T06:15:52.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-42419
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD