CVE-2018-15807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
23/08/2018
Last modified:
03/10/2019

Description

POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locally using a deterministic algorithm. This code may be generated by an attacker and used to bypass any POSIM EVO login prompt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:posim:evo:15.13:*:*:*:*:windows:*:*


References to Advisories, Solutions, and Tools