CVE-2018-17486 Vulnerability Details

  /     /     /  

CVE-2018-17486 Metadata Quick Info

CVE Published: 19/03/2019 | CVE Updated: 16/09/2024 | CVE Year: 2018
Source: ibm | Vendor: Jolly Technologies | Product: Lobby Track Desktop
Status : PUBLISHED

CVE-2018-17486 Description

Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Bypass Security
Source: Jolly Technologies

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).