CVE-2015-2909

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
06/02/2020
Last modified:
12/02/2020

Description

Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netvu:dv-ip_express_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:dv-ip_express:-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd-advanced_-_sdhd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd-advanced_-_sdhd:*:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd-advanced_8\/12\/16_vga_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd-advanced_8\/12\/16_vga:-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd_advanced_closed_iptv_\(m3u\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd_advanced_closed_iptv_\(m3u\):-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd_advanced_non_closed_iptv_\(m3u\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd_advanced_non_closed_iptv_\(m3u\):-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd_advanced_nvr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd_advanced_nvr:-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd_32_\(m3g\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netvu:sd_32_\(m3g\):-:*:*:*:*:*:*:*
cpe:2.3:o:netvu:sd_32_\(m3h\)_firmware:-:*:*:*:*:*:*:*