PT-2025-38603 · General Bytes · Crypto Application Server
General Bytes
·
Published
2025-09-19
·
Updated
2025-09-22
·
CVE-2022-4980
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
General Bytes Crypto Application Server (CAS) versions 20201208 through 20220531.38
General Bytes Crypto Application Server (CAS) version 20220725.22
Description
General Bytes Crypto Application Server (CAS) contains an authentication bypass in the admin web interface. An unauthenticated attacker can invoke a URL used for the product’s default installation/first-admin creation page to create a new administrative account remotely. Gaining admin privileges allows attackers to change ATM configurations, potentially redirecting funds. The issue was actively exploited in the wild against cloud-hosted and standalone CAS deployments, scanning exposed instances on ports 7777/443.
Recommendations
General Bytes Crypto Application Server (CAS) versions prior to 20220531.38 (backport) should be updated to version 20220531.38 or later.
General Bytes Crypto Application Server (CAS) version 20220725.22 should be updated to a newer version.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crypto Application Server