vulnerability

Password leak due to insecure default configuration

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Jun 22, 2023
Added
Jun 22, 2023
Modified
Jun 22, 2023

Description

By default, the remote administration server does not use SSL. While the password transmitted on the wire is encrypted, the encryption key is hard-coded and users' passwords can be recovered from a packet captures.

Solution

globalscape-eft-upgrade-to-8-1-0-16
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.