LOW · 2.9

CVE-2018-17489

EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of th...

Vulnerability Description

EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.

CVSS Score

2.9

LOW

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HidglobalEasylobby Solo11.0.4563

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-17489?

CVE-2018-17489 is a vulnerability with a CVSS score of 2.9 (LOW). EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of th...

How severe is CVE-2018-17489?

CVE-2018-17489 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-17489?

Check the references section above for vendor advisories and patch information. Affected products include: Hidglobal Easylobby Solo.