CVE-2018-19233

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
20/12/2018
Last modified:
08/01/2019

Description

COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:comparex:miss_marple:*:*:*:*:enterprise:*:*:* 2.0 (excluding)