Overview
The Pearson ProctorCache software uses a hard coded password for administrative tasks.
Description
| The ProctorCache is designed to cache the testing content, as well as cache the responses and maintain a client list of active test-takers. ProctorCache is a server software package installed locally within the LAN on a Windows system. CWE-259: Use of Hard-coded Password - CVE-2015-0972 | 
Impact
| An attacker on the local network can use the credentials to interrupt a test session and perform administrative tasks such as canceling tests or deleting users. According to Pearson, the actual test data is encrypted and not immediately accessible by an administrator. | 
Solution
| Apply an update | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 6.2 | AV:A/AC:L/Au:S/C:N/I:P/A:C | 
| Temporal | 5.1 | E:F/RL:OF/RC:C | 
| Environmental | 1.3 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2015-0972 | 
| Date Public: | 2015-06-15 | 
| Date First Published: | 2015-06-16 | 
| Date Last Updated: | 2015-06-16 14:32 UTC | 
| Document Revision: | 66 |