PT-2025-38603 · General Bytes · Crypto Application Server

General Bytes

·

Published

2025-09-19

·

Updated

2025-09-22

·

CVE-2022-4980

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions General Bytes Crypto Application Server (CAS) versions 20201208 through 20220531.38 General Bytes Crypto Application Server (CAS) version 20220725.22
Description General Bytes Crypto Application Server (CAS) contains an authentication bypass in the admin web interface. An unauthenticated attacker can invoke a URL used for the product’s default installation/first-admin creation page to create a new administrative account remotely. Gaining admin privileges allows attackers to change ATM configurations, potentially redirecting funds. The issue was actively exploited in the wild against cloud-hosted and standalone CAS deployments, scanning exposed instances on ports 7777/443.
Recommendations General Bytes Crypto Application Server (CAS) versions prior to 20220531.38 (backport) should be updated to version 20220531.38 or later. General Bytes Crypto Application Server (CAS) version 20220725.22 should be updated to a newer version.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-4980

Affected Products

Crypto Application Server