CVE-2022-35413

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pentasecurity:wapples:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:49

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb', 'name': 'https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb -

Information

Published : 2022-09-13 22:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-35413

Mitre link : CVE-2022-35413

CVE.ORG link : CVE-2022-35413


JSON object : View

Products Affected

pentasecurity

  • wapples
CWE
CWE-798

Use of Hard-coded Credentials