PT-2003-2308 · Aprelium Technologies · Abyss Web Server
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1363
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Aprelium Technologies Abyss Web Server versions 1.1.2 and earlier
Description
The issue concerns the remote web management interface of the affected software, which fails to log connection attempts to the web management port (9999). This oversight allows remote attackers to perform brute force attacks on the administration console without being detected.
Recommendations
For versions 1.1.2 and earlier, consider implementing logging for connection attempts to the web management port as a temporary workaround until a patch is available. Restrict access to the administration console to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Abyss Web Server