SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0972

Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this…

MEDIUM 5.0EPSS 1.36%

Does this matter?

Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.

Description

Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.36% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-255
Affected
pearson/proctorcache
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.