PT-2026-29511 · Metronik · Mepis Rm
Mijo Mišić
·
Publicado
2026-04-01
·
Atualizado
2026-04-01
·
CVE-2026-25601
CVSS v3.1
6.7
Média
| Vetor | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MEPIS RM (affected versions not specified)
Description
A security issue was found in MEPIS RM, an industrial software product by Metronik. The software includes a hardcoded cryptographic key within the
Mx.Web.ComponentModel.dll component. When the option to store domain passwords is enabled, this key is used to encrypt user passwords before they are stored in the application’s database. An attacker with the necessary privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mepis Rm