Full Report
Use of Hard-coded Credentials vulnerability (CVE-2025-13776) has been found in Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW applications.
Analysis Summary
# Vulnerability: Hard-coded Database Credentials in Multiple Finka Applications
## CVE Details
- CVE ID: CVE-2025-13776
- CVSS Score: *Score not explicitly provided, derived severity based on impact* (Likely High based on file system/database access)
- CWE: CWE-798 (Use of Hard-coded Credentials)
## Affected Systems
- Products: Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW
- Versions:
- Finka-FK (<18.5)
- Finka-KPR (<16.6)
- Finka-Płace (<13.4)
- Finka-Faktura (<18.3)
- Finka-Magazyn (<8.3)
- Finka-STW (<12.3)
- Configurations: Applicable to instances where default, hard-coded credentials are still in use.
## Vulnerability Description
Multiple applications within the Finka suite utilize hard-coded credentials for accessing the Firebird database. Critically, these credentials are *shared across all running instances* of this software. An attacker on the local network who knows these default credentials can gain unauthorized access to the database content.
## Exploitation
- Status: Not explicitly stated, assumed theoretical/local network exploit.
- Complexity: Low (Requires knowledge of default credentials and presence on the local network).
- Attack Vector: Adjacent (Local network access required).
## Impact
- Confidentiality: High (Ability to read sensitive database content).
- Integrity: High (Ability to edit sensitive database content).
- Availability: Medium (Potential to disrupt database operations through unauthorized modifications).
## Remediation
### Patches
Patches are available, upgrading to the following versions resolves the vulnerability:
- Finka-FK: Version 18.5 or later
- Finka-KPR: Version 16.6 or later
- Finka-Płace: Version 13.4 or later
- Finka-Faktura: Version 18.3 or later
- Finka-Magazyn: Version 8.3 or later
- Finka-STW: Version 12.3 or later
### Workarounds
No specific workarounds were mentioned in the provided text beyond applying the patches. General mitigation would involve network segmentation to prevent unauthorized local network access to systems running this software, if patching is not immediately possible.
## Detection
- Indicators of Compromise: Unauthorized successful Firebird database logins using known default credentials.
- Detection methods and tools: Network monitoring for unusual database connection patterns; integrity checks on application configuration files if credentials reside there.
## References
- Vendor Advisory (TIK-SOFT via CERT Polska): httpx://cert.pl/en/cve/
- Report Incident Portal: httpx://incydent.cert.pl/#!/lang=en
- CVD Process Information: httpx://cert.pl/en/cvd/