CVE-2022-25804
IGEL Universal Management Suite vulnerability analysis and mitigation

Overview

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100, where insecure permissions for the serverconfig registry key (under HKEY_LOCAL_MACHINE) allowed storage of superuser/database credentials. The vulnerability was discovered in January 2022 and publicly disclosed in May 2022 (Atredis Advisory).

Technical details

The vulnerability exists in the de.igel.rm.config.PrefDBCredentials class in RMGUI.jar, which is used to encrypt and decrypt credentials for the UMS superuser. On Windows systems, the stored credentials are located in the registry at HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Prefs\de\igel\rm\config\serverconfig as dbuser and dbpassword values. The implementation uses a hardcoded DES key in the PrefDBCredentials class for encryption and decryption of the dbpassword value (Atredis Advisory).

Impact

This vulnerability allows a low-privileged attacker with Operating System (OS) access to read the encrypted dbpassword value. Due to the hardcoded DES key in the PrefDBCredentials class, an attacker with access to the encrypted dbpassword value can decrypt the password and gain superuser/database access to IGEL UMS and its database (Atredis Advisory).

Exploitability

The vulnerability can be exploited by an attacker with low-privilege access to the operating system where IGEL UMS is installed. The attacker can read the registry values and use the hardcoded DES key to decrypt the credentials, leading to elevated access (Atredis Advisory).

Mitigation and workarounds

The vendor recommends making the UMS Server host accessible only to users that need to access UMS and keeping the UMS database and its backups under strict access control. No patches were initially available to address these findings (Atredis Advisory).

Additional resources


SourceThis report was generated using AI

Related IGEL Universal Management Suite vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-25806HIGH8.8
  • IGEL Universal Management Suite logoIGEL Universal Management Suite
  • cpe:2.3:a:igel:universal_management_suite
NoYesJun 09, 2022
CVE-2022-25805MEDIUM6.5
  • IGEL Universal Management Suite logoIGEL Universal Management Suite
  • cpe:2.3:a:igel:universal_management_suite
NoYesJun 09, 2022
CVE-2022-25807MEDIUM5.5
  • IGEL Universal Management Suite logoIGEL Universal Management Suite
  • cpe:2.3:a:igel:universal_management_suite
NoYesJun 09, 2022
CVE-2022-25804MEDIUM5.5
  • IGEL Universal Management Suite logoIGEL Universal Management Suite
  • cpe:2.3:a:igel:universal_management_suite
NoYesJun 09, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management