CVE-2022-35582
Last modified
CVE-2022-35582 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not disclosed in the documentation. Knowing the credentials, attackers can use this feature to gain uncontrolled access to the device and therefore are considered an undocumented possibility for remote control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pentasecurity | Wapples | 4.0.0 |
| Pentasecurity | Wapples | 5.0.0.0 |
| Pentasecurity | Wapples | 5.0.12.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-35582?
How severe is CVE-2022-35582?
How do I fix CVE-2022-35582?
Are you affected by CVE-2022-35582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
