Vulnerabilities > CVE-2015-0930 - Credentials Management vulnerability in Servision HVG Video Gateway Firmware 2.2.26A100/2.2.26A77

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
servision
CWE-255
critical

Summary

The web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a100 has a hardcoded administrative password, which makes it easier for remote attackers to obtain access via an HTTP session.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/135707/servisionhvg-backdoor.txt
idPACKETSTORM:135707
last seen2016-12-05
published2016-02-11
reporterRichard Tafoya
sourcehttps://packetstormsecurity.com/files/135707/Servision-HVG-Hardcoded-Credentials.html
titleServision HVG Hardcoded Credentials