top of page
perceptive_background_267k.jpg

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthentica…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 19:00:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Critical Infrastructure, Identity & Access

Care Everywhere Gateway version 14.3.10 contains a hard-coded credentials vulnerability in its bundled WildFly 8.2.0.Final management interface. The vulnerability allows unauthenticated remote attackers to gain administrative access using default credentials that are identical across all installations. Attackers can access the WildFly management console on port 20990 and deploy a malicious WAR file to achieve remote code execution as the Windows machine account. The affected version 14.x.x was declared end-of-life in 2017, meaning no patches will be issued for this branch. Newer versions of the product have addressed the vulnerability. The issue is particularly critical in healthcare environments where Care Everywhere Gateway is used for health information exchange. Exploitation requires network access to port 20990 but no authentication, making it relatively easy to exploit if the management interface is exposed.

Technical details

Mitigation steps:

Affected products:

Care Everywhere Gateway 14.3.10
WildFly 8.2.0.Final

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page