CVE Vulnerabilities

CVE-2018-17497

Initialization of a Resource with an Insecure Default

Published: Mar 21, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

Affected Software

Name Vendor Start Version End Version
Evisitorpass Thresholdsecurity 1.5.5.2 (including) 1.5.5.2 (including)

References