CVE-2025-28388

O

penC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:open_source:*:*:*

History

27 Oct 2025, 16:15

Type Values Removed Values Added
Summary (en) OpenC3 COSMOS v6.0.0 was discovered to contain hardcoded credentials for the Service Account. (en) OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
References
  • () https://github.com/OpenC3/cosmos/pull/1816 -
  • () https://github.com/OpenC3/cosmos/pull/1816/commits/195974a019f375f7c5a35f48e4151babb40649ac -
  • () https://github.com/OpenC3/cosmos/releases/tag/v6.0.2 -

17 Jun 2025, 19:41

Type Values Removed Values Added
References () https://openc3.com/ - () https://openc3.com/ - Product
References () https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/ - () https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/ - Exploit, Mitigation, Third Party Advisory
First Time Openc3 cosmos
Openc3
CPE cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:open_source:*:*:*

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Se descubrió que OpenC3 COSMOS v6.0.0 contenía credenciales codificadas para la cuenta de servicio.

13 Jun 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-798

13 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 14:15

Updated : 2025-10-27 16:15


NVD link : CVE-2025-28388

Mitre link : CVE-2025-28388

CVE.ORG link : CVE-2025-28388


JSON object : View

Products Affected
CWE
CWE-798

Use of Hard-coded Credentials