Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
General Bytes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin Page

General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation page and create a new administrative account remotely. By gaining admin privileges, the attacker can change the ATM configuration resulting in redirected funds. Public vendor adviso

CWE-306Sep 19, 2025
CVSS9.3v4.0EPSS0.813%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX