The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even though it is possible to change this by SSHing into
the device, it has remained unchanged on every installed system
observed. This account is not root but holds high-level permissions that
could severely impact the device's operation if exploited.
Metrics
Affected Vendors & Products
References
History
Fri, 30 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 May 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to change this by SSHing into the device, it has remained unchanged on every installed system observed. This account is not root but holds high-level permissions that could severely impact the device's operation if exploited. | |
Title | Consilium Safety CS5000 Fire Panel Initialization of a Resource with an Insecure Default | |
Weaknesses | CWE-1188 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-05-29T23:17:18.012Z
Updated: 2025-05-30T12:50:16.987Z
Reserved: 2025-05-15T21:07:17.944Z
Link: CVE-2025-41438

Updated: 2025-05-30T12:50:13.742Z

Status : Awaiting Analysis
Published: 2025-05-30T00:15:23.003
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-41438

No data.