CVE-2023-28725
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 20.61% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- generalbytes/crypto application server
- Source
- cve@mitre.org
References
- https://arstechnica.com/information-technology/2023/03/hackers-drain-bitcoin-atms-of-1-5-million-by-exploiting-0-day-bug/Press/Media Coverage
- https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2885222430/Security+Incident+March+17-18th+2023Exploit, Vendor Advisory
- https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/951418958/Update+CASMitigation
- https://twitter.com/generalbytes/status/1637192687160897537Issue Tracking
- https://web3isgoinggreat.com/single/general-bytes-crypto-atms-exploited-for-over-1-6-millionThird Party Advisory
- https://www.bleepingcomputer.com/news/security/general-bytes-bitcoin-atms-hacked-using-zero-day-15m-stolen/Press/Media Coverage
- https://www.generalbytes.com/en/support/changelogRelease Notes
- https://arstechnica.com/information-technology/2023/03/hackers-drain-bitcoin-atms-of-1-5-million-by-exploiting-0-day-bug/Press/Media Coverage
- https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2885222430/Security+Incident+March+17-18th+2023Exploit, Vendor Advisory
- https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/951418958/Update+CASMitigation
- https://twitter.com/generalbytes/status/1637192687160897537Issue Tracking
- https://web3isgoinggreat.com/single/general-bytes-crypto-atms-exploited-for-over-1-6-millionThird Party Advisory
- https://www.bleepingcomputer.com/news/security/general-bytes-bitcoin-atms-hacked-using-zero-day-15m-stolen/Press/Media Coverage
- https://www.generalbytes.com/en/support/changelogRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.