Vulnerability Description
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bettinivideo | Sgsetup | 4.3.0 |
Related Weaknesses (CWE)
References
- https://www.andreabruschi.net/2022/02/17/bettini-s-r-l-sgsetup-hard-coded-ssh-prExploitThird Party Advisory
- https://www.andreabruschi.net/2022/02/17/bettini-s-r-l-sgsetup-hard-coded-ssh-prExploitThird Party Advisory
FAQ
What is CVE-2022-25569?
CVE-2022-25569 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.
How severe is CVE-2022-25569?
CVE-2022-25569 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-25569?
Check the references section above for vendor advisories and patch information. Affected products include: Bettinivideo Sgsetup.