Use of hard-coded credentials in Foglight Evolve - CVE-2020-8868
Published: March 18, 2020
Foglight Evolve
Detailed vulnerability description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists within the "CommandLineService" functionality due to presence of hard-coded credentials in application code in the "__service__ user" account. A remote unauthenticated attacker can access the affected system using the hard-coded credentials for this account and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.