Lobby Track Desktop Multiple Security Vulnerabilities
BID:107413
Info
Lobby Track Desktop Multiple Security Vulnerabilities
| Bugtraq ID: | 107413 |
| Class: | Unknown |
| CVE: |
CVE-2018-17482 CVE-2018-17483 CVE-2018-17484 CVE-2018-17485 CVE-2018-17486 CVE-2018-17487 CVE-2018-17488 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 2019 12:00AM |
| Updated: | Mar 04 2019 12:00AM |
| Credit: | Hannah Robbins and Scott Brink from X-Force Red research team. |
| Vulnerable: |
Jolly Technologies Lobby Track Desktop 8.2.186 |
| Not Vulnerable: | |
Discussion
Lobby Track Desktop Multiple Security Vulnerabilities
Lobby Track Desktop is prone to the following vulnerabilities:
1. Multiple information disclosure vulnerabilities
2. A security-bypass vulnerabilities
3. An insecure default-password vulnerability
4. Multiple privilege escalation vulnerabilities
An attacker may leverage these issues to bypass security restrictions, obtain potentially-sensitive information, perform certain unauthorized actions, gain elevated privileges and gain access to the affected application.
Lobby Track Desktop version 8.2.186 is vulnerable.
Lobby Track Desktop is prone to the following vulnerabilities:
1. Multiple information disclosure vulnerabilities
2. A security-bypass vulnerabilities
3. An insecure default-password vulnerability
4. Multiple privilege escalation vulnerabilities
An attacker may leverage these issues to bypass security restrictions, obtain potentially-sensitive information, perform certain unauthorized actions, gain elevated privileges and gain access to the affected application.
Lobby Track Desktop version 8.2.186 is vulnerable.
Exploit / POC
Lobby Track Desktop Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Lobby Track Desktop Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Lobby Track Desktop Multiple Security Vulnerabilities
References:
References:
- Jolly Technologies Home Page (Jolly Technologies Inc.)
- Jolly Technologies Product Page (Jolly Technologies Inc.)
- Stranger Danger: X-Force Red Finds 19 Vulnerabilities in Visitor Management Syst (IBM)