PT-2018-10990 · Eminent · Eminent Em4544

Tomas Bortoli

·

Publicado

2018-06-17

·

Atualizado

2018-08-11

·

CVE-2018-12073

CVSS v3.1

5.3

Média

VetorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eminent EM4544 version 9.10
Description An issue allows changing the admin password to an attacker-chosen value without knowing the current password, potentially through exploitation in combination with a successful XSS or at an unattended workstation.
Recommendations For Eminent EM4544 version 9.10, consider restricting access to the web interface to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the ability to change the admin password within the web interface to require the current password.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12073

Produtos afetados

Eminent Em4544