vulnerability
Password leak due to insecure default configuration
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:P/I:N/A:N) | Jun 22, 2023 | Jun 22, 2023 | Jun 22, 2023 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Jun 22, 2023
Added
Jun 22, 2023
Modified
Jun 22, 2023
Description
By default, the remote administration server does not use SSL. While the password transmitted on the wire is encrypted, the encryption key is hard-coded and users' passwords can be recovered from a packet captures.
Solution
globalscape-eft-upgrade-to-8-1-0-16

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.