PT-2018-13219 · Posim · Posim Evo

Published

2018-08-23

·

Updated

2019-10-03

·

CVE-2018-15807

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POSIM EVO version 15.13 for Windows
Description The issue concerns an "Emergency Override" administrative account in POSIM EVO that can be accessed through the "override" feature. This feature uses a locally computed code based on a deterministic algorithm, which can potentially be generated by an attacker. As a result, an attacker may bypass the POSIM EVO login prompt.
Recommendations For POSIM EVO version 15.13 for Windows, consider disabling the "override" feature until a patch is available to prevent potential bypass of the login prompt. Restrict access to the "Emergency Override" administrative account to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15807

Affected Products

Posim Evo