CVE-2019-15015

HIGH

Zingbox Inspector < 1.294 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2019-15015

Scores

CVSS v3 8.4
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
zingbox/inspector < 1.294
Published Oct 09, 2019
Tracked Since Feb 18, 2026