CVE-2022-45766
About
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.
Rainforest analyst review
Global Facilities Management Software from Key Systems Management contains hardcoded credentials that let a remote attacker undermine the availability, confidentiality, and integrity of electronic key boxes. These are the systems that control physical key custody, so a baked-in credential doesn't just leak data, it can affect who gets physical access to keys and whether the boxes work at all.
Hardcoded-credential flaws are exploited by simply using the known account, uniformly across every deployment, with no cracking required. The distinctive risk here is the crossover into the physical world: the software governs real locks and key boxes, so a compromise has consequences that a purely digital breach doesn't. It is a niche product, which limits broad scanning interest, but for any site that runs it the stakes are concrete.
This is an asset-inventory-and-isolation problem for us. GFMS is specialized software unlikely to be tracked alongside mainstream IT, so we first need to know where it lives, then ensure it is segmented off any untrusted network since the hardcoded credential can't be changed away. Where the vendor has no fix, network isolation and monitoring of the key-box management traffic are the realistic controls.
References
Related CVEs
Frequently asked questions
What is CVE-2022-45766?
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.
How severe is CVE-2022-45766?
CVE-2022-45766 carries a CVSS 3.1 base score of 9.1, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.
How is CVE-2022-45766 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity None and availability High.
Which products are affected by CVE-2022-45766?
Public advisories list the following as affected: global facilities management software. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-45766?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
