Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27199

Опубликовано: 17 дек. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:magic_home_pro_project:magic_home_pro:1.5.1:*:*:*:*:android:*:*

EPSS

Процентиль: 91%
0.06505
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.

EPSS

Процентиль: 91%
0.06505
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287