Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-25966

Опубликовано: 28 окт. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sectona:spectra:*:*:*:*:*:*:*:*
Версия до 3.4.0 (исключая)

EPSS

Процентиль: 59%
0.00378
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value.

EPSS

Процентиль: 59%
0.00378
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306