CVE-2022-35413

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
13/09/2022
Last modified:
07/11/2023

Description

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pentasecurity:wapples:*:*:*:*:*:*:*:* 4.0.54.1 (including) 6.0.0 (including)