PT-2020-10181 · Idelji · Idelji Web Viewpoint Plus+2
Published
2020-01-27
·
Updated
2020-02-07
·
CVE-2019-19539
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ
Idelji Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR
Idelji Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF
Description
An issue was discovered in Idelji Web ViewPoint products. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.
Recommendations
For Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, restrict access to the ADB and AADB files within the Installation subvolume to prevent unauthorized password discovery.
For Idelji Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, consider disabling the feature that allows Guardian users to read ADB and AADB file content until a patch is available.
For Idelji Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF, avoid using the WVP Events screen to acknowledge events until the issue is resolved.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idelji Web Viewpoint
Idelji Web Viewpoint Enterprise
Idelji Web Viewpoint Plus