CVE-2025-28389: Critical severity OpenC3 COSMOS vulnerability
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28389?
CVE-2025-28389 is classified as a high severity vulnerability due to weak password requirements that allow for brute force attacks.
How do I fix CVE-2025-28389?
To fix CVE-2025-28389, you should implement strong password policies and utilize an account lockout mechanism to prevent repeated login attempts.
Which versions of OpenC3 COSMOS are affected by CVE-2025-28389?
CVE-2025-28389 affects OpenC3 COSMOS version 6.0.0 across both enterprise and open source variants.
What type of attack can exploit CVE-2025-28389?
CVE-2025-28389 can be exploited through brute force attacks that can bypass authentication due to weak password requirements.
Is there a patch available for CVE-2025-28389?
Currently, there is no specific patch available for CVE-2025-28389, but it is recommended to enhance password policies as an immediate measure.