PT-2018-1150 · Docutrac · Office Therapy+1

Publicado

2018-02-09

·

Atualizado

2019-10-09

·

CVE-2018-5551

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DocuTrac QuicDoc and Office Therapy versions with DTISQLInstaller.exe version 1.6.4.0 and prior
Description The issue is related to the use of predefined credentials in the DTISQLInstaller.exe executable file. This allows a remote attacker to gain access to the software using the QDMaster, OTMaster, and sa accounts.
Recommendations For versions with DTISQLInstaller.exe version 1.6.4.0 and prior, consider changing the predefined credentials QDMaster, OTMaster, and sa to secure passwords to prevent unauthorized access. As a temporary workaround, restrict access to the DTISQLInstaller.exe executable file until a secure version is available.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00587
CVE-2018-5551

Produtos afetados

Docutrac Quicdoc
Office Therapy