PT-2018-10990 · Eminent · Eminent Em4544
Tomas Bortoli
·
Publicado
2018-06-17
·
Atualizado
2018-08-11
·
CVE-2018-12073
CVSS v3.1
5.3
Média
| Vetor | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Eminent EM4544 version 9.10
Description
An issue allows changing the admin password to an attacker-chosen value without knowing the current password, potentially through exploitation in combination with a successful XSS or at an unattended workstation.
Recommendations
For Eminent EM4544 version 9.10, consider restricting access to the web interface to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the ability to change the admin password within the web interface to require the current password.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eminent Em4544