Vulnerability CVE-2018-17486


Published: 2019-03-21

Description:
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host.

Type:

CWE-254

(Security Features)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial
Affected software
Jollytech -> Lobby track 

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/149646

Copyright 2024, cxsecurity.com

 

Back to Top