CVE-2017-14728
Description
Use of hard-coded credentials in Orpak SiteOmat BOS allows remote attackers to authenticate without authorization, leading to full system compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Use of hard-coded credentials in Orpak SiteOmat BOS allows remote attackers to authenticate without authorization, leading to full system compromise.
Vulnerability
Use of hard-coded credentials (CWE-798) in Orpak SiteOmat BOS allows remote attackers to authenticate without authorization. The application utilizes hard-coded username and password credentials for application login, affecting all SiteOmat BOS versions prior to a patched release [1]. The advisory notes that the software does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public exploitation.
Exploitation
An attacker can exploit this vulnerability remotely without any prior authentication or user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N). By simply using the hard-coded credentials, the attacker gains access to the web and SSH interfaces. No special privileges or network position is required beyond network access to the affected system.
Impact
Successful exploitation results in unauthorized access to view and edit monitoring, configuration, and payment information. The advisory warns that this could lead to arbitrary remote code execution and denial-of-service conditions, potentially compromising the entire fuel station management system [1].
Mitigation
Orpak has released software updates to address the vulnerability; consult the vendor for the specific patched version. As a workaround, administrators should change all default passwords immediately. The advisory recommends updating to the latest version of SiteOmat BOS [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Orpak/SiteOmatdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- www.orpak.com/allproducts/siteomat-station-controller-sw/nvdProductVendor Advisory
- www.securityfocus.com/bid/108167nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-122-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.