PT-2021-20011 · Unknown · Intellibridge Ec 60+1
Andrea Palanca
+2
·
Published
2021-12-27
·
Updated
2022-01-10
·
CVE-2021-32993
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IntelliBridge EC 40 and 60 Hub versions C.00.04 and prior
Description
The issue concerns hard-coded credentials, such as a password or a cryptographic key, used for inbound authentication, outbound communication to external components, or encryption of internal data.
Recommendations
For versions C.00.04 and prior, consider changing the hard-coded credentials to unique, secure credentials to mitigate the risk of exploitation. As a temporary workaround, restrict access to the affected system until a patch or update is available.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellibridge Ec 40
Intellibridge Ec 60