CVE-2022-4980 is a critical authentication bypass vulnerability affecting General Bytes Crypto Application Server (CAS) versions prior to 20220531.38 (backport) and 20220725.22 (mainline). An unauthenticated attacker could create a new administrative account by accessing a specific URL intended for initial setup, leading to full control over ATM configurations and potential fund redirection. With a CVSS score of 9.3 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity, allowing for high impact on confidentiality, integrity, and availability. The issue was actively exploited in the wild against cloud-hosted and standalone CAS deployments, though public exploit code and significant community discussion are currently absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| General Bytes | Crypto Application Server (CAS) | >= 20201208, < 20220531.38, >= 20201208, < 20220725.22CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.