Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2025122401124848 | Publication Time | 2025/12/24 13:35 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/12/24 13:35 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】iCHEF Technology | Enterprise Cloud Database – Hard-coded Cryptographic Key (CVE-2025-15016) |
|||
| [Content] Forwarded from TWCERTCC-200-202512-00000012 【iCHEF Technology | Enterprise Cloud Database – Hard-coded Cryptographic Key】 (CVE-2025-15016, CVSS: 9.8) A Hard-coded Cryptographic Key vulnerability exists in the Enterprise Cloud Database developed by iCHEF Technology. An unauthenticated remote attacker can use a fixed key to generate authentication information, thereby logging into the system as an arbitrary user. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] Enterprise Cloud Database |
|||
| [Recommended Actions] Enterprise Cloud Database Contact the vendor to install the patch |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-132-10587-797c6-1.html |
|||