CVE-2023-37755 Information
Description
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://medium.com/@ray.999/d7a54030e055 https://github.com/leekenghwa/CVE-2023-37755—Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below/blob/main/README.md https://medium.com/@ray.999/i-doit-v25-and-below-incorrect-access-control-issue-cve-2023-37755-d7a54030e055
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: