Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.
History

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Eppendorf
Eppendorf bioflo 320
Vendors & Products Eppendorf
Eppendorf bioflo 320

Tue, 26 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted.
Title Eppendorf BioFlo 320 Use of hard-coded password
Weaknesses CWE-259
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-05-26T17:06:46.563Z

Updated: 2026-05-26T18:39:20.583Z

Reserved: 2026-04-27T18:37:39.380Z

Link: CVE-2026-7251

cve-icon Vulnrichment

Updated: 2026-05-26T18:39:14.922Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-26T18:16:55.347

Modified: 2026-05-26T19:06:14.330

Link: CVE-2026-7251

cve-icon Redhat

No data.