IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
The vulnerability consists of the presence of static, hard-coded credentials (CWE-798) in the software that can be used for incoming authentication, communication with external components, or encryption of internal data. An attacker who learns these credentials (e.g., through software analysis) can use them to gain access to the device or systems communicating with it. Since the attack requires no authentication or user interaction, and the attack vector is network-based, the barrier to entry is very low.
An attacker can gain unauthorized access to the system, take control of protected data, or disrupt the operation of security infrastructure components, leading to violations of data confidentiality and integrity.
Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7177447
IBM Security Verify Access Appliance in versions 10.0.0 through 10.0.8 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LIBM Security Verify Access
APPIbm10.0.0 – 10.0.8
Related vulnerabilities
Privilege escalation do root w IBM Security Verify Access i Verify Identity Access
IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)
IBM Security Verify Access — zdalne wykonanie poleceń (command injection)
IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik