PT-2003-2308 · Aprelium Technologies · Abyss Web Server

Publicado

2003-12-31

·

Atualizado

2008-09-05

·

CVE-2003-1363

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Aprelium Technologies Abyss Web Server versions 1.1.2 and earlier
Description The issue concerns the remote web management interface of the affected software, which fails to log connection attempts to the web management port (9999). This oversight allows remote attackers to perform brute force attacks on the administration console without being detected.
Recommendations For versions 1.1.2 and earlier, consider implementing logging for connection attempts to the web management port as a temporary workaround until a patch is available. Restrict access to the administration console to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1363

Produtos afetados

Abyss Web Server