The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://www.trustwave.com/spiderlabs/advisories/TWSL2011-001.txt | vendor advisory |
http://securitytracker.com/id?1025447 | vdb entry |