Search

Find a vulnerability

Search criteria

    2 vulnerabilities by fydeos

    CVE-2024-25825 (GCVE-0-2024-25825)

    Vulnerability from nvd – Published: 2024-10-09 00:00 – Updated: 2024-10-10 15:37
    VLAI
    Summary
    FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 15:03 UTC
    CWE
    • n/a
    • CWE-259 - Use of Hard-coded Password
    Impacted products
    Vendor Product Version
    fydeos fydeos Affected: 17.1_r114
    Affected: 17.0_r114
        cpe:2.3:o:fydeos:fydeos:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fydeos openfyde Affected: r114
        cpe:2.3:o:fydeos:openfyde:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:fydeos:fydeos:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fydeos",
                "vendor": "fydeos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "17.1_r114"
                  },
                  {
                    "status": "affected",
                    "version": "17.0_r114"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fydeos:openfyde:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "openfyde",
                "vendor": "fydeos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "r114"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25825",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T15:03:30.207049Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-259",
                    "description": "CWE-259 Use of Hard-coded Password",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T15:37:49.835Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-09T15:34:18.552Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://fydeos.io/"
            },
            {
              "url": "https://openfyde.io/"
            },
            {
              "url": "https://github.com/openFyde/"
            },
            {
              "url": "https://gist.github.com/hchasens/d20dff418f6908dc96e65f4e43a058f1"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-25825",
        "datePublished": "2024-10-09T00:00:00.000Z",
        "dateReserved": "2024-02-12T00:00:00.000Z",
        "dateUpdated": "2024-10-10T15:37:49.835Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-25825 (GCVE-0-2024-25825)

    Vulnerability from cvelistv5 – Published: 2024-10-09 00:00 – Updated: 2024-10-10 15:37
    VLAI
    Summary
    FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 15:03 UTC
    CWE
    • n/a
    • CWE-259 - Use of Hard-coded Password
    Impacted products
    Vendor Product Version
    fydeos fydeos Affected: 17.1_r114
    Affected: 17.0_r114
        cpe:2.3:o:fydeos:fydeos:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fydeos openfyde Affected: r114
        cpe:2.3:o:fydeos:openfyde:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:fydeos:fydeos:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fydeos",
                "vendor": "fydeos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "17.1_r114"
                  },
                  {
                    "status": "affected",
                    "version": "17.0_r114"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fydeos:openfyde:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "openfyde",
                "vendor": "fydeos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "r114"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-25825",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T15:03:30.207049Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-259",
                    "description": "CWE-259 Use of Hard-coded Password",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T15:37:49.835Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-09T15:34:18.552Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://fydeos.io/"
            },
            {
              "url": "https://openfyde.io/"
            },
            {
              "url": "https://github.com/openFyde/"
            },
            {
              "url": "https://gist.github.com/hchasens/d20dff418f6908dc96e65f4e43a058f1"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-25825",
        "datePublished": "2024-10-09T00:00:00.000Z",
        "dateReserved": "2024-02-12T00:00:00.000Z",
        "dateUpdated": "2024-10-10T15:37:49.835Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }