arstechnica.com
https://arstechnica.com/information-technology/2023/03/hackers-drain-bitcoin-atms-of-1-5-million-by-exploiting-0-day-bug CVE-2023-28725
CRITICAL
generalbytes crypto_application_server Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2023-28725 has a selected CVSS score of 9.1 (critical).
Description
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 21, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
crypto_application_serverBrowse generalbytes / crypto_application_server | VulnCheck | Version data not supplied | |
References
8generalbytes.atlassian.net
https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2885222430/Security+Incident+March+17-18th+2023 generalbytes.atlassian.net
https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/951418958/Update+CAS nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-28725 twitter.com
https://twitter.com/generalbytes/status/1637192687160897537 web3isgoinggreat.com
https://web3isgoinggreat.com/single/general-bytes-crypto-atms-exploited-for-over-1-6-million bleepingcomputer.com
https://www.bleepingcomputer.com/news/security/general-bytes-bitcoin-atms-hacked-using-zero-day-15m-stolen generalbytes.com
https://www.generalbytes.com/en/support/changelog