CVE-2022-35413

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Configurations

Configuration 1

cpe:2.3:a:pentasecurity:wapples:*:*:*:*:*:*:*:*

Information

Published : 2022-09-13 10:15

Updated : 2022-10-01 02:28


NVD link : CVE-2022-35413

Mitre link : CVE-2022-35413

Products Affected
No products.
CWE