First published: Fri Oct 12 2018(Updated: )
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Nuuo Nuuo Cms | <=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17894 is considered a critical vulnerability due to the presence of hard-coded passwords allowing unauthorized privileged access.
To fix CVE-2018-17894, upgrade to a version of NUUO CMS later than 3.1 where hard-coded passwords are addressed.
CVE-2018-17894 allows attackers to exploit default accounts with hard-coded passwords, potentially leading to complete system compromise.
All users of NUUO CMS version 3.1 and prior are affected by CVE-2018-17894.
There are no effective workarounds for CVE-2018-17894; upgrading to a newer version is the recommended solution.