Back to overview

CVE-2026-7251

CRITICAL
9.8
CVSS 3.1
Description
Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.

Metadata

CVE ID
CVE-2026-7251
State
PUBLISHED
Assigner
icscert
Reserved
2026-04-27 18:37 UTC
Published
2026-05-26 17:06 UTC
Last updated
2026-06-04 21:10 UTC
Primary CWE
CWE-259
CWE-259 Use of hard-coded password
Vendor / Product
Eppendorf / BioFlo 320
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Eppendorf BioFlo 320 All
Weakness (CWE)
CWESourceDescription
CWE-259 cna CWE-259 Use of hard-coded password
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview