Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-14930

Опубликовано: 19 июн. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 4.3
EPSS Низкий

Описание

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bt_ctroms_terminal_project:bt_ctroms_terminal:-:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05816
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

EPSS

Процентиль: 90%
0.05816
Низкий

8.1 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319