An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/160623/Programi-Bilanc-Build-007-Release-014-31.01.2020-Weak-Default-Password.html | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2020/Dec/34 | Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/160623/Programi-Bilanc-Build-007-Release-014-31.01.2020-Weak-Default-Password.html | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2020/Dec/34 | Mailing List Third Party Advisory |
Configurations
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/160623/Programi-Bilanc-Build-007-Release-014-31.01.2020-Weak-Default-Password.html - Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2020/Dec/34 - Mailing List, Third Party Advisory |
Information
Published : 2020-12-23 16:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11720
Mitre link : CVE-2020-11720
CVE.ORG link : CVE-2020-11720
JSON object : View
Products Affected
bilanc
- bilanc
CWE
CWE-798
Use of Hard-coded Credentials