CVE-2021-45877

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
21/03/2022
Last modified:
28/03/2022

Description

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:garo:wallbox_gtb_firmware:*:*:*:*:*:*:*:* 185 (including)
cpe:2.3:h:garo:wallbox_gtb:-:*:*:*:*:*:*:*
cpe:2.3:o:garo:wallbox_gtc_firmware:*:*:*:*:*:*:*:* 185 (including)
cpe:2.3:h:garo:wallbox_gtc:-:*:*:*:*:*:*:*
cpe:2.3:o:garo:wallbox_glb_firmware:*:*:*:*:*:*:*:* 185 (including)
cpe:2.3:h:garo:wallbox_glb:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools