Impact
The vulnerability resides in Care Everywhere Gateway version 14.3.10, where the bundled WildFly 8.2.0.Final management console uses hard‑coded default credentials. An unauthenticated attacker can log in to the console on port 20990 and deploy a malicious web archive via the Deployments interface. Successful deployment gives the attacker the ability to execute arbitrary code with the privileges of the Windows machine account, effectively compromising the host.
Affected Systems
Care Everywhere Gateway from Care Everywhere LLC, specifically version 14.3.10 of the 14.x.x series, is affected. The entire 14.x.x line was declared end‑of‑life in 2017 and is no longer supported; newer releases of the product have removed the vulnerable WildFly component.
Risk and Exploitability
The CVSS score of 9.3 marks the flaw as critical, while an EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Attackers only need to reach the open WildFly management port 20990 over the network and supply the known default credentials to gain full administrative access. From there, deploying a malicious WAR file results in remote code execution under the Windows machine account.
OpenCVE Enrichment