HIGH
hard coded credentials in elvexys ISOS firmwares
Published Dec 28, 2022
7.8
HIGHCVSS 3.1
EPSS 0.15%
Description
ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.
Affected products
-
- Version 1.81StatusaffectedConstraints<=2.00
- Version
- ≥ 1.81 · ≤ 2.00
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
ISOS firmwares from version 2.01 force the user to change the default credentials during the first login. For ISOS fimwares up to version 2.00, the default credentials must be changed by the user as documented in the « Initial staging » and « User access » chapters.
Weaknesses (1)
References (1)
- https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/ release-notesRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/ | release-notesRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NCSC.ch
Published Dec 28, 2022
Updated Apr 10, 2025
Reserved Dec 28, 2022
Link CVE-2022-4780
CISA Vulnrichment
Updated Apr 10, 2025