CyberRota Analysis
AI-GeneratedThe Care Everywhere Gateway 14.3.10 on Windows contains a critical vulnerability due to hard-coded credentials in the WildFly management interface, allowing unauthenticated remote attackers to gain administrative access. This flaw enables attackers to deploy malicious applications, leading to potential remote code execution with the privileges of the Windows machine account. Organizations still using version 14.x.x, which has been end-of-life since 2017, should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.