MEDIUM · 5.0

CVE-2011-0756

The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote conso...

Vulnerability Description

The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
TrustwaveWebdefend<= 3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0756?

CVE-2011-0756 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote conso...

How severe is CVE-2011-0756?

CVE-2011-0756 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0756?

Check the references section above for vendor advisories and patch information. Affected products include: Trustwave Webdefend.