PT-2026-50569 · Vantage6 · Vantage6
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
vantage6 versions prior to 5.0.0
Description
An open-source infrastructure for privacy preserving analysis provides an initial user with the username
root and password root. This configuration is insecure as attackers are aware that most servers possess a root user with administrative privileges, and the default password is weak and may not be reset by administrators.Recommendations
Update to version 5.0.0.
As a temporary workaround, delete the
root user after it has been used to create other users.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vantage6