CVE-2021-45877
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
21/03/2022
Last modified:
28/03/2022
Description
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:garo:wallbox_gtb_firmware:*:*:*:*:*:*:*:* | 185 (including) | |
| cpe:2.3:h:garo:wallbox_gtb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:garo:wallbox_gtc_firmware:*:*:*:*:*:*:*:* | 185 (including) | |
| cpe:2.3:h:garo:wallbox_gtc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:garo:wallbox_glb_firmware:*:*:*:*:*:*:*:* | 185 (including) | |
| cpe:2.3:h:garo:wallbox_glb:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



