Back

CRITICAL

Use of Hard-coded Credentials Optigo Networks ONS NC600

Published May 6, 2025

Description

In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command executions.

Affected products

Remediation

Vendor solution

Optigo Networks recommends users implement at least one of the following additional mitigations:

* Use a dedicated NIC on the BMS computer and exclusively use the computer for connecting to OneView to manage your OT network configuration. * Set up a router firewall with a white list for the devices permitted to access OneView. * Connect to OneView via secure VPN.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published May 6, 2025
Updated May 6, 2025
Reserved Apr 28, 2025
CISA Vulnrichment
Updated May 6, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published May 6, 2025
Updated May 6, 2025
Exploited since n/a
EUVD-2025-13635