PT-2020-7825 · Dedicated Micros · Ecosense+4

Andrew Tierney

·

Published

2020-02-06

·

Updated

2020-02-12

·

CVE-2015-2909

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices (affected versions not specified)
Description: The issue arises because the devices rely on a GUI warning to ensure administrators configure login credentials. This makes it easier for remote attackers to obtain access in situations where the warning was not heeded. The vendor notes that clear warnings are presented on the GUI to set usernames and passwords.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2909

Affected Products

Ds2
Dedicated Micros Dv-Ip Express
Ecosense
Sd
Sd Advanced