Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)

A popular Chinese document management system has been found to be vulnerable to basic security threats due to its use of well-known default passwords. ESAFENET’s Content Data Guard (CDG) 3, a product marketed as a secure solution for document management and data leakage prevention, has been targeted by scans looking to exploit these weaknesses.

The company behind CDG 3, ESAFENET, appears to have focused primarily on the Chinese market with its security-focused solutions. Unfortunately, despite its claims of providing robust security measures, the product has shown vulnerabilities in the past, including a cross-site scripting (XSS) flaw that was made public earlier. This time around, scans are targeting the default passwords that ESAFENET CDG ships with, rather than the previously disclosed XSS vulnerability.

The issue lies in the fact that these default passwords, although they may seem secure at first glance due to their complexity and adherence to common password guidelines (10 characters, including numbers, special characters, upper/lower case), are actually well-known and easily guessable. This is particularly concerning as they are likely to pass many standard security checks, which can create a false sense of security among users.

The scans we’ve seen involve attempts to log in to the CDG 3 system using these default passwords. The request itself appears harmless, with the attacker simply sending a login request with the well-known password “Est@Spc820”. This is a prime example of how an attack can be carried out without raising immediate suspicion. It’s only when you examine the code that you realize the significance of this vulnerability.

This incident serves as a stark reminder that even reputable security products can have vulnerabilities, and default passwords should never be used in production environments. Organizations using ESAFENET CDG 3 or similar solutions should take immediate action to change these default passwords and implement additional security measures to mitigate potential risks.

In light of this discovery, it’s essential for organizations to regularly review their systems’ default settings and ensure that they are not using vulnerable configurations. This includes changing default passwords, keeping software up-to-date, and implementing robust security protocols to prevent unauthorized access. By being proactive about security, you can minimize the risk of falling victim to attacks like this one.


Source: SANS ISC — 2026-07-26