CVE-2025-30183 Details
Description
CyberData 011209 Intercom does not properly store or protect web server admin credentials.
A vulnerability exists in the CyberData 011209 SIP Emergency Intercom, specifically in versions prior to 22.0.1, due to improper storage and protection of web server admin credentials. This weakness could allow an unauthenticated user to access sensitive information or disrupt system operations.
Users are advised to update the intercom software to version 22.0.1. For additional guidance, refer to the CISA recommendations for minimizing network exposure of control system devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cyberdata 011209 sip emergency intercom firmware | < 22.0.1 |
CPE
Remediation
| |
| cyberdata 011209 sip emergency intercom | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | Initial Analysis | [email protected] |
| Jun 9, 2025 | New CVE Received | [email protected] |