CVE-2023-42419
Last modified
CVE-2023-42419 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected. . EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-42419?
How severe is CVE-2023-42419?
How do I fix CVE-2023-42419?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-42398An issue in zzCMS v.2023 allows a remote attacker to execute…9.8
- CVE-2023-42399Cross Site Scripting vulnerability in xdsoft.net Jodit Edito…6.1
- CVE-2023-42404OneVision Workspace before WS23.1 SR1 (build w31.040) allows…9.8
- CVE-2023-42405SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 al…9.8
- CVE-2023-42406SQL injection vulnerability in D-Link Online behavior audit …9.8
- CVE-2023-4241lol-html can cause panics on certain HTML inputs. Anyone pro…7.5
- CVE-2023-4242The FULL - Customer plugin for WordPress is vulnerable to In…4.3
- CVE-2023-42425An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows…9.8
- CVE-2023-42426Cross-site scripting (XSS) vulnerability in Froala Froala Ed…6.1
- CVE-2023-42427Cross-site scripting vulnerability exists in UNIVERSAL PASSP…6.5
- CVE-2023-42428Directory traversal vulnerability in CubeCart prior to 6.5.3…6.5
- CVE-2023-42429Improper buffer restrictions in some Intel NUC BIOS firmware…7.8
Are you affected by CVE-2023-42419?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
