Security restrictions bypass in Energy Management Suite - CVE-2018-0468

 

Security restrictions bypass in Energy Management Suite - CVE-2018-0468

Published: December 4, 2018


Vulnerability identifier: #VU16235
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0468
CWE-ID: CWE-798
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to the installation of the PostgreSQL database with unchanged default access credentials. A local authenticated attacker can log in to the machine where CEMS is installed, establish a local connection to the database and bypass security restrictions to access and alter confidential data.


Affected software

Energy Management Suite

How to mitigate CVE-2018-0468

Users of existing installations can change the database access password by following the instructions in the Release Notes document under the "Reset PostgreSQL database password" section.


External References

Related Security Bulletins