PT-2022-22977 · Vinchin+1 · Vinchin Backup & Recovery+1

Esjay

·

Published

2022-07-08

·

Updated

2024-01-26

·

CVE-2022-35866

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vinchin Backup and Recovery version 6.5.0.17561
Description This issue allows remote attackers to bypass authentication on affected installations. The specific flaw exists within the configuration of the MySQL server, which uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system.
Recommendations For Vinchin Backup and Recovery version 6.5.0.17561, consider changing the hard-coded password for the administrator user in the MySQL server configuration as a temporary workaround until a patch is available. Restrict access to the MySQL server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-35866
ZDI-22-959

Affected Products

Mysql Server
Vinchin Backup & Recovery