Overview
The Pearson ProctorCache software uses a hard coded password for administrative tasks.
Description
The ProctorCache is designed to cache the testing content, as well as cache the responses and maintain a client list of active test-takers. ProctorCache is a server software package installed locally within the LAN on a Windows system. CWE-259: Use of Hard-coded Password - CVE-2015-0972 |
Impact
An attacker on the local network can use the credentials to interrupt a test session and perform administrative tasks such as canceling tests or deleting users. According to Pearson, the actual test data is encrypted and not immediately accessible by an administrator. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.2 | AV:A/AC:L/Au:S/C:N/I:P/A:C |
Temporal | 5.1 | E:F/RL:OF/RC:C |
Environmental | 1.3 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2015-0972 |
Date Public: | 2015-06-15 |
Date First Published: | 2015-06-16 |
Date Last Updated: | 2015-06-16 14:32 UTC |
Document Revision: | 66 |