PT-2018-10990 · Eminent · Eminent Em4544
Tomas Bortoli
·
Published
2018-06-17
·
Updated
2018-08-11
·
CVE-2018-12073
CVSS v3.1
5.3
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Eminent EM4544 version 9.10
Description
An issue allows changing the admin password to an attacker-chosen value without knowing the current password, potentially through exploitation in combination with a successful XSS or at an unattended workstation.
Recommendations
For Eminent EM4544 version 9.10, consider restricting access to the web interface to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit the ability to change the admin password within the web interface to require the current password.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eminent Em4544