Vulnerability Description
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cs-Technologies | Evolution | <= 2.04.560 |
Related Weaknesses (CWE)
References
- https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiThird Party Advisory
- https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiThird Party Advisory
FAQ
What is CVE-2024-29844?
CVE-2024-29844 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the appl...
How severe is CVE-2024-29844?
CVE-2024-29844 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-29844?
Check the references section above for vendor advisories and patch information. Affected products include: Cs-Technologies Evolution.