CVE-2022-35413
13.09.2022, 22:15
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.Enginsight
Vendor | Product | Version |
---|---|---|
pentasecurity | wapples | 4.0.54.1 ≤ 𝑥 ≤ 6.0.0 |
𝑥
= Vulnerable software versions
References