Overview
The PolyVision RoomWizard web based scheduling system with touch screen display contains two vulnerabilities that allow an unauthorized user to access the device console and Sync Connector Active Directory credentials.
Description
The PolyVision RoomWizard is a touch screen scheduling device with a web-based administrative interface. The Sync Connector feature allows the RoomWizard to communicate with Microsoft Exchange in an Microsoft Windows Actitve Directory (AD) environment. The Sync Connector AD credentials are disclosed in the content of a web page on the administrative interface. This vulnerability has been reported to be affected in RoomWizard firmware version 3.2.3. An additional issue exists in that the RoomWizard ships with a default password on the administrator account permitting console access via HTTP. |
Impact
An attacker with HTTP access to a RoomWizard device and knowledge of the administrative password could obtain the AD credentials. The attacker could also modify settings, including network configuration, which could prevent legitimate users from accessing the RoomWizard device. |
Solution
Change default passwords |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Sean Lam for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2010-0214 |
Severity Metric: | 1.26 |
Date Public: | 2011-01-07 |
Date First Published: | 2011-01-07 |
Date Last Updated: | 2011-01-07 12:55 UTC |
Document Revision: | 32 |