#VU66683 Improper access control in Crypto Application Server (CAS)
Published: August 22, 2022
Crypto Application Server (CAS)
General Bytes
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access restrictions to the default installation page. A remote attacker can connect to the default installation URL and create an administrative user account.
Note, the vulnerability is being active exploited in the wild.