CVE-2024-28744
HIGHDescription
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.
Is your site exposed to CVE-2024-28744?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-28744? +
How severe is CVE-2024-28744? +
How do I check if I'm vulnerable to CVE-2024-28744? +
Related Vulnerabilities
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems …
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access …
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to …
A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. …