PT-2019-9670 · Tightrope Media Systems · Tightrope Media Carousel Seneca Hdn
Drew Green
·
Published
2019-10-29
·
Updated
2019-11-05
·
CVE-2018-18929
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tightrope Media Carousel Seneca HDn version 7.0.4.104
Description
The issue concerns a default local administrator username and password that can be discovered by a limited user account. This sensitive information is stored in an "unattend.xml" file on the C: drive, which is a leftover from the Sysprep process. An attacker who obtains this username and password can use it to gain administrator-level access to the system.
Recommendations
For version 7.0.4.104, change the default local administrator username and password to unique and secure credentials to prevent unauthorized access. Additionally, consider restricting access to the "unattend.xml" file to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tightrope Media Carousel Seneca Hdn