PT-2022-11700 · Aquaview · Aquaview

Published

2022-02-07

·

Updated

2022-02-15

·

CVE-2021-42833

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AquaView versions 1.60, 7.x, and 8.x
Description A Use of Hardcoded Credentials issue exists that could allow an authenticated local attacker to manipulate users and system settings.
Recommendations For AquaView version 1.60, update to a version that does not use hardcoded credentials. For AquaView versions 7.x, update to a version that does not use hardcoded credentials. For AquaView versions 8.x, update to a version that does not use hardcoded credentials. As a temporary workaround, consider restricting access to system settings to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42833

Affected Products

Aquaview