VulnerabilityModified
CVE-2022-35413
WAPPLES through 6.0 has a hardcoded systemi account.
CRITICAL 9.8EPSS 18.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.98% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- pentasecurity/wapples
- Source
- cve@mitre.org
References
- https://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=OverviewPatch, Product, Third Party Advisory, Vendor Advisory
- https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb
- https://www.pentasecurity.com/product/wapples/Product, Vendor Advisory
- https://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=OverviewPatch, Product, Third Party Advisory, Vendor Advisory
- https://medium.com/%40_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb
- https://www.pentasecurity.com/product/wapples/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.