PT-2018-13219 · Posim · Posim Evo
Publicado
2018-08-23
·
Atualizado
2019-10-03
·
CVE-2018-15807
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
POSIM EVO version 15.13 for Windows
Description
The issue concerns an "Emergency Override" administrative account in POSIM EVO that can be accessed through the "override" feature. This feature uses a locally computed code based on a deterministic algorithm, which can potentially be generated by an attacker. As a result, an attacker may bypass the POSIM EVO login prompt.
Recommendations
For POSIM EVO version 15.13 for Windows, consider disabling the "override" feature until a patch is available to prevent potential bypass of the login prompt. Restrict access to the "Emergency Override" administrative account to minimize the risk of exploitation.
Correção
Use of Insufficiently Random Values
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Posim Evo