PT-2018-15355 · Safe · Fme Server

Publicado

2018-12-23

·

Atualizado

2019-10-03

·

CVE-2018-20402

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Safe Software FME Server versions prior to 2018.1
Description The issue allows unauthorized access by creating and enabling three additional accounts with default passwords. The accounts have usernames that are the same as their passwords: guest, user, and author. These accounts are granted default privilege roles, which can be exploited by logging in with these credentials.
Recommendations For Safe Software FME Server versions prior to 2018.1, change the default passwords of the guest, user, and author accounts to secure passwords to prevent unauthorized access. Consider disabling these accounts if they are not necessary for the system's operation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20402

Produtos afetados

Fme Server