CVE-2025-3920 Details
Description
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extract these credentials, potentially leading to a complete compromise of the application's administrative functions. This issue was fixed in version 2025.03.27 of the SUR-FBD CMMS software.
A vulnerability exists in SUR-FBD CMMS due to hard-coded credentials embedded in a compiled DLL file. These credentials are linked to a built-in administrative account. An attacker with local access to the system or the application's installation directory could extract these credentials, potentially leading to a full compromise of the application's administrative functions. This vulnerability affects all versions of SUR-FBD CMMS prior to 2025.03.27.
Users can upgrade to SUR-FBD CMMS version 2025.03.27 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2025CISA-ADP
Assessed Jul 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/07/CVE-2025-3920/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SUR-FBD CMMS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2025 | New CVE Received | [email protected] |
Volerion