CVE Vulnerabilities

CVE-2024-29844

Use of Default Credentials

Published: Apr 15, 2024 | Modified: Apr 15, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Default credentials on the Web Interface of Evolution Controller 2.x (123 and 123) allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.

Weakness

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Potential Mitigations

References