Vulnerability Description
POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locally using a deterministic algorithm. This code may be generated by an attacker and used to bypass any POSIM EVO login prompt.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Posim | Evo | 15.13 |
Related Weaknesses (CWE)
References
- https://versprite.com/advisories/posim-evo-for-windows/Third Party Advisory
- https://versprite.com/advisories/posim-evo-for-windows/Third Party Advisory
FAQ
What is CVE-2018-15807?
CVE-2018-15807 is a vulnerability with a CVSS score of 7.8 (HIGH). POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's "override" feature. This Override prompt expects a code that is computed locall...
How severe is CVE-2018-15807?
CVE-2018-15807 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15807?
Check the references section above for vendor advisories and patch information. Affected products include: Posim Evo.