PT-2021-11798 · Unknown · Mbconnect24
Published
2021-02-16
·
Updated
2021-02-19
·
CVE-2020-35567
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
mbCONNECT24 versions through 2.6.2
mymbCONNECT24 versions through 2.6.2
Description:
The software uses a secure password for database access, but this password is shared across instances.
Recommendations:
For mbCONNECT24 versions through 2.6.2, consider changing the shared database access password to unique passwords for each instance.
For mymbCONNECT24 versions through 2.6.2, consider changing the shared database access password to unique passwords for each instance.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mbconnect24