CVE-2020-11543

CRITICAL

OpsRamp Gateway < 7.0.0 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user accounts for the gateway appliance.

Scores

CVSS v3 9.8
EPSS 0.0260
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
opsramp/gateway 3.0.0
Published Apr 08, 2020
Tracked Since Feb 18, 2026