CVE-2022-25806: High severity igel universal management suite vulnerability
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25806?
CVE-2022-25806 has been classified as a high severity vulnerability due to the potential for unauthorized access to superuser credentials.
How do I fix CVE-2022-25806?
To mitigate CVE-2022-25806, upgrade to a version of IGEL Universal Management Suite that addresses this hardcoded DES key issue.
What are the risks associated with CVE-2022-25806?
The risks include the potential for attackers to decrypt superuser credentials, leading to unauthorized access and control over affected systems.
Who is affected by CVE-2022-25806?
Organizations using IGEL Universal Management Suite version 6.07.100 are at risk from CVE-2022-25806.
What products are impacted by CVE-2022-25806?
CVE-2022-25806 impacts the IGEL Universal Management Suite version 6.07.100 specifically.