CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Scans for ESAFENET CDG 3 Document Management System Weak Logins

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3228

As cited

Copy frozen at (site build).

vulnerabilities

Scans for ESAFENET CDG 3 Document Management System Weak Logins

ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.

Why it matters: Organizations running ESAFENET CDG must immediately change all default passwords and audit for unauthorized access, as exploit code for these credentials is publicly available and actively being used in scanning campaigns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Scans for ESAFENET CDG 3 Document Management System Weak Logins

ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.

Why it matters: Organizations running ESAFENET CDG must immediately change all default passwords and audit for unauthorized access, as exploit code for these credentials is publicly available and actively being used in scanning campaigns.

VendorsGitHubLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary