General Bytes Vulnerabilities and Affected Products
Vulnerabilities associated with General Bytes Crypto Application Server (CAS).
Products
Clear product- Crypto Application Server (CAS)1 vulnerability
- General Bytes Crypto Application Server (CAS)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4980CRITICAL | General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin PageGeneral Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation page and create a new administrative account remotely. By gaining admin privileges, the attacker can change the ATM configuration resulting in redirected funds. Public vendor adviso… CWE-306Sep 19, 2025 | CVSS9.3v4.0 | EPSS0.813% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |