An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1393 | |
Metrics |
cvssV3_1
|
Tue, 11 Mar 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-11T19:27:40.631Z
Reserved: 2025-02-14T00:00:00.000Z
Link: CVE-2025-26701

Updated: 2025-03-11T19:27:37.517Z

Status : Received
Published: 2025-03-11T18:15:33.210
Modified: 2025-03-11T18:15:33.210
Link: CVE-2025-26701

No data.