Percona PMM Server Default Credentials Vulnerability Leading to SSH Access and Privilege Escalation

Vulnerability

A vulnerability exists in Percona PMM Server (OVA) versions prior to 3.0.0-1.ova, specifically in OVA installations of PMM 2.38 and above. This issue arises from default service account credentials that can be exploited to gain unauthorized SSH access, escalate privileges to root using sudo, and access sensitive data. The vulnerability does not affect PMM Docker or Amazon Machine Images (AMIs).

Impact

Exploitation of this vulnerability allows for unauthorized SSH access, privilege escalation to root via sudo, and potential exposure of sensitive service credentials and configurations.

Remediation

Users are advised to upgrade to PMM 2.44.0-1 or PMM 3.0.0-1. Instructions for downloading these versions are available on the Percona website. After upgrading, all credentials for monitored and connected services should be changed, and system and authentication logs should be reviewed for any signs of unauthorized access.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.