CVE-2020-36915
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798, CWE-1392
- Source
- disclosure@vulncheck.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/190628
- https://packetstorm.news/files/id/159709
- https://www.adtecdigital.com
- https://www.exploit-db.com/exploits/48954
- https://www.vulncheck.com/advisories/adtec-digital-signedje-digital-signage-player-default-credentials
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5603.php
- https://www.exploit-db.com/exploits/48954
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.