Vulnerability CVE-2020-11720


Published: 2020-12-23

Description:
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Programi Bilanc Build 007 Release 014 31.01.2020 Weak Default Password
Georg Ph E Heise
19.12.2020

Type:

CWE-798

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Bilanc -> Bilanc 

 References:
http://packetstormsecurity.com/files/160623/Programi-Bilanc-Build-007-Release-014-31.01.2020-Weak-Default-Password.html
http://seclists.org/fulldisclosure/2020/Dec/34

Copyright 2024, cxsecurity.com

 

Back to Top