Hardcoded Credentials Vulnerability in Pro-face GP-Pro EX by Pro-face
CVE-2015-7921

9.1CRITICAL

Key Information:

Summary

The FTP server in Pro-face GP-Pro EX products contains hardcoded credentials that may allow remote attackers to bypass authentication easily. This vulnerability impacts versions before 4.05.000 of several Pro-face software products including GP-Pro EX EX-ED, PFXEXEDV, PFXEXEDLS, and PFXEXGRPLS. By exploiting this flaw, malicious actors can gain unauthorized access to sensitive data and functionalities, potentially leading to further security breaches.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.