Vulnerabilities > Pentasecurity

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-31322 Use of Hard-coded Credentials vulnerability in Pentasecurity Wapples 5.0.12.0/6.0.0/V6.0.R3.4.10
Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.
local
low complexity
pentasecurity CWE-798
7.8
2022-09-13 CVE-2022-31324 Download of Code Without Integrity Check vulnerability in Pentasecurity Wapples
An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.
network
low complexity
pentasecurity CWE-494
6.5
2022-09-13 CVE-2022-35413 Use of Hard-coded Credentials vulnerability in Pentasecurity Wapples
WAPPLES through 6.0 has a hardcoded systemi account.
network
low complexity
pentasecurity CWE-798
critical
9.8
2022-09-13 CVE-2022-35582 Use of Hard-coded Credentials vulnerability in Pentasecurity Wapples 4.0.0/5.0.0.0/5.0.12.0
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control.
network
low complexity
pentasecurity CWE-798
8.8