CVE-2022-3010
02.01.2024, 19:15
The Priva TopControl Suite containspredictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.Enginsight
Vendor | Product | Version |
---|---|---|
priva | top_control_suite | 𝑥 ≤ 8.7.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1391 - Use of Weak CredentialsThe product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
- CWE-916 - Use of Password Hash With Insufficient Computational EffortThe software generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.