Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18929

Опубликовано: 29 окт. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 4
EPSS Низкий

Описание

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:trms:seneca_hdn_firmware:*:*:*:*:*:*:*:*
Версия до 7.0.4.104 (включая)
cpe:2.3:h:trms:seneca_hdn:-:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00288
Низкий

8.8 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system.

EPSS

Процентиль: 52%
0.00288
Низкий

8.8 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-798