Description
Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_confirm
https://github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4
Patch, Third Party Advisory x_refsource_misc
https://github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc42ae4b1d050a87
Patch, Third Party Advisory x_refsource_misc
https://github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4fee
Patch, Third Party Advisory x_refsource_misc
https://github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4c080
Scores
CVSS v3
7.2
EPSS
0.0148
EPSS Percentile
70.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-321
CWE-798
Status
published
Products (4)
gravitl/netmaker
< 0.8.5
gravitl/netmaker
0 - 0.8.5Go
gravitl/netmaker
0.9.0 - 0.9.4Go
netmaker/netmaker
< 0.8.5
Published
Feb 18, 2022
Tracked Since
Feb 18, 2026