CVE-2024-29844 CRITICAL

CVE-2024-29844: Default credentials on web interface of Evolution Controller Versions allows attackers to login and perform administrative functions

Vendor Cs Technologies Australia
Product Evolution Controller
Weakness CWE-1392
Published April 14, 2024
Last update September 25, 2024

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.

Key dates

02Disclosure timeline

April 14, 2024 CVE published
September 25, 2024 Record updated