# Connector security patch advisory - password

<br>

Product: Cloudbrink Connector&#x20;

Release: All&#x20;

Date: 12 July 2025&#x20;

#### &#x20;Summary

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">JIRA ID </td><td valign="top">CBOPS-4120 </td></tr><tr><td valign="top">Detected Date </td><td valign="top">July 10 2025 </td></tr><tr><td valign="top">Fixed Date </td><td valign="top">July 12 2025 </td></tr><tr><td valign="top">Component </td><td valign="top">Brink Connector </td></tr><tr><td valign="top">Severity </td><td valign="top">Critical </td></tr><tr><td valign="top">Impact </td><td valign="top">Administrative access due to default credentials not changed post deployment </td></tr><tr><td valign="top">Known affected incidents </td><td valign="top">None </td></tr></tbody></table>

<br>

#### &#x20;Description&#x20;

Brink Connector component deployed prior to version 12.x or earlier (and later upgraded) contained the default ubuntu account in unlocked state. If the default credentials are not changed by the system administrator, this would allow a user, who has the information about Connector private IP and access to the DMZ network, to login using the default ubuntu account and gain administrative access.

<br>

#### Applied Fix&#x20;

Cloudbrink has disabled the default ubuntu account on all the Connectors deployed by the customers and made the account defunct with immediate effect. There is no impact on the Cloudbrink service to the users due to the applied fix.&#x20;

#### Customer Action Required&#x20;

No action is expected by the customers&#x20;

#### Contact&#x20;

For any further information, please contact <security@cloudbrink.com>&#x20;


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.cloudbrink.com/release-notes/security-advisory/connector-security-patch-advisory-password.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
