CVE-2025-28388

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:open_source:*:*:*

History

27 Oct 2025, 16:15

Type Values Removed Values Added
References
  • () https://github.com/OpenC3/cosmos/pull/1816 -
  • () https://github.com/OpenC3/cosmos/pull/1816/commits/195974a019f375f7c5a35f48e4151babb40649ac -
  • () https://github.com/OpenC3/cosmos/releases/tag/v6.0.2 -
Summary (en) OpenC3 COSMOS v6.0.0 was discovered to contain hardcoded credentials for the Service Account. (en) OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

17 Jun 2025, 19:41

Type Values Removed Values Added
CPE cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:open_source:*:*:*
First Time Openc3 cosmos
Openc3
References () https://openc3.com/ - () https://openc3.com/ - Product
References () https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/ - () https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/ - Exploit, Mitigation, Third Party Advisory

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Se descubrió que OpenC3 COSMOS v6.0.0 contenía credenciales codificadas para la cuenta de servicio.

13 Jun 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-798

13 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 14:15

Updated : 2025-10-27 16:15


NVD link : CVE-2025-28388

Mitre link : CVE-2025-28388

CVE.ORG link : CVE-2025-28388


JSON object : View

Products Affected

openc3

  • cosmos
CWE
CWE-798

Use of Hard-coded Credentials