Vulnerability Description
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trustwave | Webdefend | <= 3.0 |
Related Weaknesses (CWE)
References
- http://securitytracker.com/id?1025447
- https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txtVendor Advisory
- http://securitytracker.com/id?1025447
- https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txtVendor Advisory
FAQ
What is CVE-2011-0756?
CVE-2011-0756 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote conso...
How severe is CVE-2011-0756?
CVE-2011-0756 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0756?
Check the references section above for vendor advisories and patch information. Affected products include: Trustwave Webdefend.