a certificate and its private key are installed in the Windows machine
certificate store using Network and Security tool, access rights to the private
key are unnecessarily
granted to the operator group.
* Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed
*
Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable
Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . | |
| Title | Unnecessary permissions on private keys of certificates installed by Network and Security Wizard | |
| First Time appeared |
Codra
Codra panorama Suite |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:codra:panorama_suite:*:*:windows:*:*:*:*:* cpe:2.3:a:codra:panorama_suite:panorama_suite_2025_updated_dec._25:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Codra
Codra panorama Suite |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CODRA
Published:
Updated: 2026-03-25T13:06:43.166Z
Reserved: 2026-03-24T09:12:20.014Z
Link: CVE-2026-4761
Updated: 2026-03-25T13:06:38.567Z
Status : Awaiting Analysis
Published: 2026-03-25T13:16:28.310
Modified: 2026-03-25T15:41:33.977
Link: CVE-2026-4761
No data.
OpenCVE Enrichment
No data.