ICSA-13-038-01A
·
Published 2025-06-06
·
View on CISA ICS-CERT ↗
360 Systems Image Server 2000 Series Remote Root Access
CVSS 10.0
CRITICAL
CVEs (1)
Remediations
- 360 Systems has not produced a patch, new version, or firmware upgrade that removes the hardcoded password or root user account. The vendor recommends that these devices be placed on closed, nonpublic-facing networks. The vendor further recommends the use of properly configured firewalls to restrict access to only necessary ports and the use of Virtual Private Networks if access is required. For more information on proper setup of this device, users may contact 360 Systems’ customer service department.
- The operations manuals for each of these devices states: The server is designed to be used in a private dedicated video network. A firewall must be used in systems that require internal security or connection to public networks. Consult with a network security specialist for guidance on the best hardware, programming and practices for your facility’s requirements.
Affected Vendors
360 Systems
Affected Products (3)
360 Systems
·
Image server 2000
vers:all/*
360 Systems
·
Image Server Maxx
vers:all/*
360 Systems
·
Maxx
vers:all/*
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more