CVE-2022-35413
About
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
Rainforest analyst review
WAPPLES ships with a hardcoded 'systemi' account, and anyone who reaches the /webapi/ URI over HTTPS can authenticate as it to read system configuration and confidential material including SSL keys. The bitter irony is that WAPPLES is itself a web application firewall, a device organizations put at the perimeter to protect everything else. A backdoor account with no way for the operator to change or disable it turns the guard into the easiest door.
Hardcoded credentials are the lowest-effort exploitation there is: once the account is public knowledge it works everywhere the product is deployed, identically, forever, until the vendor removes it. Security appliances are attractive because they are internet-facing by design and trusted implicitly, and the specific prize here, SSL private keys, is worse than a single-host compromise; it enables decryption and impersonation of the traffic the appliance was defending.
Our angle is to treat any confirmed exposure as a key-compromise event, not just a patch ticket. Beyond inventorying which WAPPLES units we run and cutting off external access to the management API, we would plan to rotate the SSL keys and any secrets that appliance held, on the assumption they may already have walked out the /webapi/ door.
References
Related CVEs
Frequently asked questions
What is CVE-2022-35413?
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.
How severe is CVE-2022-35413?
CVE-2022-35413 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-35413 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-35413?
Public advisories list the following as affected: wapples. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-35413?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
