CVE-2024-43423
CRITICALDescription
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| doverfuelingsolutions | progauge_maglink_lx_console_firmware |
| doverfuelingsolutions | progauge_maglink_lx_console |
| doverfuelingsolutions | progauge_maglink_lx4_console_firmware |
| doverfuelingsolutions | progauge_maglink_lx4_console |
References
Other References
Frequently Asked Questions
What is CVE-2024-43423? +
How severe is CVE-2024-43423? +
What products are affected by CVE-2024-43423? +
How do I check if I'm vulnerable to CVE-2024-43423? +
Related Vulnerabilities
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond …
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password …
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services …
Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the …
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. …
A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 …