PT-2011-1359 · Polyvision · Polyvision Roomwizard

Publicado

2011-01-12

·

Atualizado

2017-08-17

·

CVE-2010-0214

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PolyVision RoomWizard version 3.2.3
Description The issue concerns the administrative interface of the PolyVision RoomWizard, where the Sync Connector Active Directory credentials are placed in a web form accessed over HTTP on port 80. This allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the "/admin/sign/DeviceSynch" API endpoint.
Recommendations For PolyVision RoomWizard version 3.2.3, consider disabling access to the /admin/sign/DeviceSynch API endpoint until a secure method of handling credentials is implemented. Restrict access to the administrative interface to minimize the risk of exploitation. Avoid using HTTP for sensitive operations; instead, use HTTPS to encrypt the communication.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0214

Produtos afetados

Polyvision Roomwizard