Sceawere

Vulnerability Detail

CVE-2026-73778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Credential Manager Default Password Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
4h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-09-01T21:18:44.627Z",
  "pubdate": "2026-09-01T21:18:44.627Z",
  "executiveSummary": "A critical security vulnerability exists within the Credential Manager component, facilitating unauthorized administrative access to affected devices. This vulnerability stems from the use of predictable factory-default credentials, which remain active during the initial setup phase, specifically in factory-default or post-ZTP (Zero Touch Provisioning) states.\nThe vulnerability allows an unauthenticated, remote attacker to gain full administrative control of the system by successfully authenticating with these known default credentials. This represents a significant security risk, as the exploitation window occurs precisely when the device is most vulnerable—before any administrator has established secure, personalized credentials.\nThe impact of successful exploitation is total system compromise, granting the attacker the ability to execute administrative functions, modify system configurations, or deploy persistent malicious payloads. Because the flaw is inherent to the initial provisioning process, the risk is particularly elevated for devices deployed into network environments without immediate security hardening. Defensive posture is severely compromised if devices are exposed to network traffic prior to the completion of the onboarding security workflow.",
  "technicalDetails": "The vulnerability resides within the Credential Manager component, which is responsible for mediating authentication requests during the device initialization and provisioning lifecycle. The root cause is the implementation of a predictable factory-default authentication mechanism that is globally applicable to all devices of the affected class, rather than utilizing unique, per-device entropy for the initial authentication token.\nThe exploitation flow begins when an unauthenticated remote attacker identifies a device in its factory-default or post-ZTP state. During the initial provisioning phase, the Credential Manager service remains active and accessible over the management interface. Because the device has not yet undergone the secure onboarding process, it relies on static credentials that do not require rotation or uniqueness.\nThe attacker initiates a session against the Credential Manager via the standard management protocol. By providing the predictable factory-default password, the attacker circumvents the authentication barrier. Once the credential check is successfully bypassed, the Credential Manager grants the attacker a session token associated with the highest privilege level, typically administrative (root/superuser).\nUpon establishing this session, the attacker possesses the full capability to issue commands to the device's administrative API. This access allows the attacker to bypass further intended configuration steps, such as setting up individual administrator accounts or enforcing access control lists. The attacker can effectively seize control of the device's management plane, leading to complete compromise of the hardware platform.\nThis vulnerability is classified as an authentication bypass through the utilization of default credentials. It is primarily a network-exposed threat if the device is connected to an untrusted network during the deployment process before administrative hardening is completed. The state of the device—specifically the transition between the factory-default image and the post-ZTP configuration—serves as the primary attack vector. The lack of dynamic authentication enforcement during this transition period allows the attacker to maintain persistence even after the device attempts to finalize its initial setup."
}
CVE-2026-73778: Credential Manager Default Password Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere