Vulnerability Description
An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prise | Adas | 1.7.0 |
References
- http://www.adas-sso.com/es/extra/download.phpProduct
- https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adasPatchThird Party Advisory
- http://www.adas-sso.com/es/extra/download.phpProduct
- https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adasPatchThird Party Advisory
FAQ
What is CVE-2019-15088?
CVE-2019-15088 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.
How severe is CVE-2019-15088?
CVE-2019-15088 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15088?
Check the references section above for vendor advisories and patch information. Affected products include: Prise Adas.