Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Prashant Pandey

Pesquisador deIndian Computer Emergency Response Team (CERT-In)
#22400de 53,635
10CVSS total
Vulnerabilidades · 1
PT-2023-17238
10
2023-04-27
Gajshield · Gajshield Data Security Firewall · CVE-2023-1778
**Name of the Vulnerable Software and Affected Versions** GajShield Data Security Firewall versions prior to v4.28 (except v4.21) **Description** This issue exists due to insecure default credentials, allowing a remote attacker to login as a superuser by using the default username and password via the web-based management interface and/or exposed SSH port. This enables remote attackers to execute arbitrary commands with administrative privileges on the targeted systems. **Recommendations** For versions prior to v4.28 (except v4.21), the vulnerability has been addressed by forcing the user to change their default password to a new non-default password.