Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18283 | A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers. |
Mon, 27 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers. | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. |
| References |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openc3
Openc3 cosmos |
|
| CPEs | cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:enterprise:*:*:* cpe:2.3:a:openc3:cosmos:6.0.0:*:*:*:open_source:*:*:* |
|
| Vendors & Products |
Openc3
Openc3 cosmos |
Fri, 13 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-526 | |
| Metrics |
cvssV3_1
|
Fri, 13 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-27T15:19:38.462Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28381
Updated: 2025-06-13T16:06:36.544Z
Status : Modified
Published: 2025-06-13T14:15:20.177
Modified: 2025-10-27T16:15:39.003
Link: CVE-2025-28381
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:13Z
EUVD