A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extract these credentials, potentially leading to a complete compromise of the application's administrative functions. This issue was fixed in version 2025.03.27 of the SUR-FBD CMMS software.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2025/07/CVE-2025-3920/ |
Configurations
No configuration.
History
08 Jul 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-07 09:15
Updated : 2025-07-08 16:18
NVD link : CVE-2025-3920
Mitre link : CVE-2025-3920
CVE.ORG link : CVE-2025-3920
JSON object : View
Products Affected
No product.
CWE
CWE-259
Use of Hard-coded Password