CVE Feed

    Dashboard / CVE / CVE-2023-1778

    CVE-2023-1778

    This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems. The vulnerability has been addressed by forcing the user to change their default password to a new non-default password.

    Published:Apr 27, 2023
    Last Modified:Jan 30, 2025
    EPS:Apr 27, 2023
    EPSS Score:0.00263
    CVSS Score:10

    Affected Products

    Vendor
    Gajshield
    Product
    Data Security Firewall
    Vendor
    Gajshield
    Product
    Data Security Firewall Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High