CVE-2023-39420
CRITICALResortData Internet Reservation Module Next Generation - Use of Hard-coded Credentials in RDPCore.dll
Title source: llmDescription
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and connect to application customers. Given that this is an administrative account, anyone logging into a customer deployment has full, unrestricted access to the application.
References (1)
Core 1
Core References
Scores
CVSS v3
9.9
EPSS
0.0055
EPSS Percentile
41.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-798
Status
published
Products (1)
resortdata/internet_reservation_module_next_generation
5.3.2.15
Published
Sep 07, 2023
Tracked Since
Feb 18, 2026