PT-2024-23082 · Unknown · Evolution Controller
Published
2024-04-14
·
Updated
2024-09-25
·
CVE-2024-29844
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Evolution Controller versions 2.x
Description
The issue concerns default credentials on the Web Interface of the affected software, allowing unauthorized access to perform administrative functions. Upon installation or first login, the application does not prompt the user to change the default password, and there is no warning about this potential security risk.
Recommendations
For Evolution Controller versions 2.x, change the default password immediately after installation or first login to prevent unauthorized access. As a temporary workaround, consider restricting access to the Web Interface until the default password is changed.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolution Controller