CVE-2025-41438 – “CS5000 Fire Panel Default Account Privilege Escalation”

The following table lists the changes that have been made to the
CVE-2025-41438 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 30, 2025

    Action Type Old Value New Value
    Added Description The CS5000 Fire Panel is vulnerable due to a default account that exists
    on the panel. Even though it is possible to change this by SSHing into
    the device, it has remained unchanged on every installed system
    observed. This account is not root but holds high-level permissions that
    could severely impact the device’s operation if exploited.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-1188
    Added Reference https://www.cisa.gov/news-events/ics-advisories/icsa-25-148-03
    Added Reference https://www.consiliumsafety.com/en/support/
Share the Post:

Related Posts