ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-35413
+3 in the same advisory: …35582 …31322 …31324
WAPPLES through 6.0 has a hardcoded systemi account.

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

NVD description · AI analysis pending
9.8
group max
14%
  • pentasecurity wapples