Vulnerability CVE-2018-15807


Published: 2018-08-23

Description:
POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locally using a deterministic algorithm. This code may be generated by an attacker and used to bypass any POSIM EVO login prompt.

Type:

CWE-330

(Use of Insufficiently Random Values)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Posim -> EVO 

 References:
https://versprite.com/advisories/posim-evo-for-windows/

Copyright 2024, cxsecurity.com

 

Back to Top