CVE-2022-35413

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pentasecurity:wapples:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:11

Type Values Removed Values Added
References () https://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=Overview - Patch, Product, Third Party Advisory, Vendor Advisory () https://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=Overview - Patch, Product, Third Party Advisory, Vendor Advisory
References () https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb - () https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb -
References () https://www.pentasecurity.com/product/wapples/ - Product, Vendor Advisory () https://www.pentasecurity.com/product/wapples/ - Product, Vendor Advisory

07 Nov 2023, 03:49

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb', 'name': 'https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb -

Information

Published : 2022-09-13 22:15

Updated : 2024-11-21 07:11


NVD link : CVE-2022-35413

Mitre link : CVE-2022-35413

CVE.ORG link : CVE-2022-35413


JSON object : View

Products Affected

pentasecurity

  • wapples
CWE
CWE-798

Use of Hard-coded Credentials