PT-2025-20825 · Unknown+2 · Actualizer+2

Published

2025-05-13

·

Updated

2025-05-22

·

CVE-2025-47276

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Actualizer versions prior to 1.2.0
Description: The issue concerns the use of OpenSSL's -passwd function, which utilizes SHA512 for password hashing, a less suitable algorithm. All Actualizer users building a full Debian Operating System are affected. The estimated number of potentially affected devices is not specified. To resolve the issue, users should upgrade to version 1.2.0 of Actualizer. For existing OS deployments, manual password changes are required against the root and Alpha accounts. The change will deploy Debian's yescript, overriding the older SHA512 hash created by OpenSSL.
Recommendations: For versions prior to 1.2.0, upgrade to version 1.2.0 of Actualizer. As a temporary workaround, users need to reset both root and Alpha users' passwords. Restrict access to the root and Alpha accounts until the issue is resolved by changing their passwords.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-47276
GHSA-V626-CHV9-V9QR

Affected Products

Actualizer
Debian
Openssl