CVE-2023-39420

CRITICAL

ResortData Internet Reservation Module Next Generation - Use of Hard-coded Credentials in RDPCore.dll

Title source: llm
STIX 2.1

Description

The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and connect to application customers. Given that this is an administrative account, anyone logging into a customer deployment has full, unrestricted access to the application.

Scores

CVSS v3 9.9
EPSS 0.0055
EPSS Percentile 41.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
resortdata/internet_reservation_module_next_generation 5.3.2.15
Published Sep 07, 2023
Tracked Since Feb 18, 2026