vendor:
Lansweeper
by:
Amel BOUZIANE-LEBLOND
9.8
CVSS
CRITICAL
Exploit
284
CWE
Product Name: Lansweeper
Affected Version From: 6.0.x
Affected Version To: 7.2.x
Patch Exists: YES
Related CWE: CVE-2020-14011
CPE: //a:lansweeper
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Incorrect Access Control
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments features.
Mitigation:
Restrict access to the console and configure what users can see or do once they've been granted access. Assign a built-in or custom user role, a set of permissions, to user groups or individual user accounts.