MidnightBSD

Advisories for hidglobal

CVE-2018-17489 LOW

EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.

CVSS 2.0

Severity: LOW

Problem Type: CWE-312,

Products Affected

Vendor Product Version
hidglobal easylobby_solo 11.0.4563
CVE-2018-17490 LOW

EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.

CVSS 2.0

Severity: LOW

Problem Type: CWE-862,

Products Affected

Vendor Product Version
hidglobal easylobby_solo 11.0.4563
CVE-2018-17491 HIGH

EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-862,

Products Affected

Vendor Product Version
hidglobal easylobby_solo 11.0.4563
CVE-2018-17492 LOW

EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

CVSS 2.0

Severity: LOW

Problem Type: CWE-798,

Products Affected

Vendor Product Version
hidglobal easylobby_solo 11.0.4563