vendor:
DeviceViewer
by:
Alessandro Magnosi
8.8
CVSS
HIGH
Arbitrary Password Change
20
CWE
Product Name: DeviceViewer
Affected Version From: 3.12.0.1
Affected Version To: 3.12.0.1
Patch Exists: YES
Related CWE: N/A
CPE: a:sricam:deviceviewer:3.12.0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
DeviceViewer 3.12.0.1 – Arbitrary Password Change
A vulnerability in Sricam DeviceViewer 3.12.0.1 allows an attacker to change the password of any registered user by creating a malicious payload file and setting it as the old password when changing the password. The new password can be set to whatever the attacker wants. To confirm the password change, the application must be restarted and the new password can be used to log in.
Mitigation:
Users should update to the latest version of Sricam DeviceViewer to ensure that the vulnerability is patched.