漏洞描述
WAPPLES Web Application Firewall through 6.0 contains a hardcoded credentials vulnerability. It contains a hardcoded system account accessible via db/wp.no1, as configured in the /opt/penta/wapples/script/wcc_auto_scaling.py file. An attacker can use this account to access system configuration and confidential information, such as SSL keys, via an HTTPS request to the /webapi/ URI on port 443 or 5001.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
medium.comhttps://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35413↗azuremarketplace.microsoft.comhttps://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=Overview↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-35413↗www.pentasecurity.comhttps://www.pentasecurity.com/product/wapples/↗