CVE-2018-17894: Critical severity nuuo cms vulnerability
Published Oct 12, 2018
·Updated
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.
Affected Software
1 affected component
NUUO NUUO CMS<=3.1
Remediation
Patch Available
Event History
Oct 12, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17894?
CVE-2018-17894 is considered a critical vulnerability due to the presence of hard-coded passwords allowing unauthorized privileged access.
2
How do I fix CVE-2018-17894?
To fix CVE-2018-17894, upgrade to a version of NUUO CMS later than 3.1 where hard-coded passwords are addressed.
3
What impact does CVE-2018-17894 have on NUUO CMS?
CVE-2018-17894 allows attackers to exploit default accounts with hard-coded passwords, potentially leading to complete system compromise.
4
Who is affected by CVE-2018-17894?
All users of NUUO CMS version 3.1 and prior are affected by CVE-2018-17894.
5
Is there a workaround for CVE-2018-17894?
There are no effective workarounds for CVE-2018-17894; upgrading to a newer version is the recommended solution.