漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
Vulnerability Description
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1392
Vulnerability Title
Care Everywhere Gateway 信任管理问题漏洞
Vulnerability Description
Care Everywhere Care Everywhere Gateway是Care Everywhere公司的一款连接医院系统的网关设备。 Care Everywhere Gateway 14.3.10版本存在信任管理问题漏洞,该漏洞源于自带WildFly管理接口中存在硬编码凭据,允许未认证远程攻击者通过默认凭据获得管理权限并部署恶意WAR文件实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A