NetBird VPN Default Password Vulnerability in Admin Account
Vulnerability
A vulnerability exists in NetBird VPN when installed using the vendor's provided script, as it fails to remove or change the default password of an admin account created by ZITADEL, the default identity provider. This issue also affects Docker installations if the default password was not changed or the admin user was not removed. All versions prior to 0.57.0 are vulnerable.
Impact
Exploitation of this vulnerability allows unauthorized access to the admin account, potentially leading to unauthorized administrative actions within the NetBird VPN application.
Remediation
Users can upgrade to NetBird VPN version 0.57.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
