CVE-2022-35413
pentasecurity wapples Use of Hard-coded Credentials
Record summary
CVE-2022-35413 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryCRITICALWAPPLES Web Application Firewall <=6.0 - Hardcoded CredentialsCVSS 9.8
WAPPLES Web Application Firewall through 6.0 contains a hardcoded credentials vulnerability. It contains a hardcoded system account accessible via db/wp.no1, as configured in the /opt/penta/wapples/script/wcc_auto_scaling.py file. An attacker can use this account to access system configuration and confidential information, such as SSL keys, via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to the WAPPLES Web Application Firewall.
Remediation
Upgrade to a version of WAPPLES Web Application Firewall that does not contain hardcoded credentials or apply the vendor-provided patch to fix the vulnerability.
Source: ProjectDiscovery