Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-37755

Опубликовано: 14 сент. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:i-doit:i-doit:*:*:*:*:open:*:*:*
Версия до 25 (включая)
cpe:2.3:a:i-doit:i-doit:*:*:*:*:pro:*:*:*
Версия до 25 (включая)

EPSS

Процентиль: 80%
0.01433
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

EPSS

Процентиль: 80%
0.01433
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798