CVE-2025-46352 – “CS5000 Fire Panel Hard-Coded Password Remote Command Injection Vulnerability”

The following table lists the changes that have been made to the
CVE-2025-46352 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 30, 2025

    Action Type Old Value New Value
    Added Description The CS5000 Fire Panel is vulnerable due to a hard-coded password that
    runs on a VNC server and is visible as a string in the binary
    responsible for running VNC. This password cannot be altered, allowing
    anyone with knowledge of it to gain remote access to the panel. Such
    access could enable an attacker to operate the panel remotely,
    potentially putting the fire panel into a non-functional state and
    causing serious safety issues.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-798
    Added Reference https://www.cisa.gov/news-events/ics-advisories/icsa-25-148-03
    Added Reference https://www.consiliumsafety.com/en/support/
Share the Post:

Related Posts