CVE-2024-28744
HIGHDescription
The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.
Is your site exposed to CVE-2024-28744?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-28744? +
How severe is CVE-2024-28744? +
How do I check if I'm vulnerable to CVE-2024-28744? +
Related Vulnerabilities
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password …
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems …
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with …
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access …
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to …