SB2024040229 - Empty Password in Configuration File in FURUNO SYSTEMS ACERA 9010
Published: April 2, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Empty Password in Configuration File (CVE-ID: CVE-2024-28744)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the password is empty and the remote access service is enabled. A remote attacker on the local network can log in to the product with no password and obtain and/or alter information.
Remediation
Install update from vendor's website.