PT-2020-7825 · Dedicated Micros · Ecosense+4
Andrew Tierney
·
Published
2020-02-06
·
Updated
2020-02-12
·
CVE-2015-2909
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices (affected versions not specified)
Description:
The issue arises because the devices rely on a GUI warning to ensure administrators configure login credentials. This makes it easier for remote attackers to obtain access in situations where the warning was not heeded. The vendor notes that clear warnings are presented on the GUI to set usernames and passwords.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ds2
Dedicated Micros Dv-Ip Express
Ecosense
Sd
Sd Advanced