CVE-2018-15807

POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locally using a deterministic algorithm. This code may be generated by an attacker and used to bypass any POSIM EVO login prompt.
Configurations

Configuration 1 (hide)

cpe:2.3:a:posim:evo:15.13:*:*:*:*:windows:*:*

History

21 Nov 2024, 03:51

Type Values Removed Values Added
References () https://versprite.com/advisories/posim-evo-for-windows/ - Third Party Advisory () https://versprite.com/advisories/posim-evo-for-windows/ - Third Party Advisory

Information

Published : 2018-08-23 20:29

Updated : 2024-11-21 03:51


NVD link : CVE-2018-15807

Mitre link : CVE-2018-15807

CVE.ORG link : CVE-2018-15807


JSON object : View

Products Affected

posim

  • evo
CWE
CWE-330

Use of Insufficiently Random Values