CVE-2017-14728 describes a critical authentication bypass vulnerability affecting all versions of Orpak SiteOmat BOS prior to the exploit's submission, stemming from an unknown area of the source code. This flaw, coupled with the system's failure to enforce password changes for administrators, leaves SSH and HTTP remote authentication exposed. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low complexity, allowing for complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact on gas station automation systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.414.084CPE matchmatch criteria | cpe:2.3:a:orpak:siteomat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.