Lucene search

K
cve[email protected]CVE-2015-3001
HistoryJun 08, 2015 - 2:59 p.m.

CVE-2015-3001

2015-06-0814:59:09
CWE-255
web.nvd.nist.gov
28
sysaid
help desk
vulnerability
hardcoded password
cve-2015-3001
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.005

Percentile

77.5%

SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

Affected configurations

NVD
Node
sysaidsysaidRange15.1
VendorProductVersionCPE
sysaidsysaidcpe:/a:sysaid:sysaid::::

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.005

Percentile

77.5%