A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges to root access with the same credentials.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/144259/DlxSpot-Hardcoded-Password.html | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-09-21 09:29
Updated : 2017-09-29 06:52
NVD link : CVE-2017-12928
Mitre link : CVE-2017-12928
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
tecnovision
- dlx_spot_player4