CVE-2015-2909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
06/02/2020
Last modified:
12/02/2020
Description
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netvu:dv-ip_express_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:dv-ip_express:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd-advanced_-_sdhd_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd-advanced_-_sdhd:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd-advanced_8\/12\/16_vga_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd-advanced_8\/12\/16_vga:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd_advanced_closed_iptv_\(m3u\)_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd_advanced_closed_iptv_\(m3u\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd_advanced_non_closed_iptv_\(m3u\)_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd_advanced_non_closed_iptv_\(m3u\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd_advanced_nvr_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd_advanced_nvr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd_32_\(m3g\)_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netvu:sd_32_\(m3g\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netvu:sd_32_\(m3h\)_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



