PT-2023-30801 · Unknown · Smartstar Software Cws

Kun Xian Lin

·

Published

2023-12-15

·

Updated

2023-12-21

·

CVE-2023-48374

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SmartStar Software CWS (affected versions not specified)
Description The issue is related to the use of a hard-coded account with low privilege in SmartStar Software CWS, a web-based integration platform. An unauthenticated remote attacker can exploit this to run partial processes and obtain partial information, but cannot disrupt service or obtain sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-48374

Affected Products

Smartstar Software Cws