Skip to main content

Vendor archive

igel CVEs

Beta · best-effort

5 CVEs tagged to vendor igel0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-47827

Published Jun 5, 2025

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be…

CVSS 4.6 · Medium
evidence mentions
10
Buzz score
73.5
KEV listedPublic PoC observed

CVE-2022-25807

Published Jun 9, 2022

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25806

Published Jun 9, 2022

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25805

Published Jun 9, 2022

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_load_mgt_tree command allows an a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25804

Published Jun 9, 2022

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HK…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1