Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-9389

Опубликовано: 03 фев. 2021
Источник: nvd
CVSS3: 3.7
CVSS2: 4.3
EPSS Низкий

Описание

A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squaredup:squaredup:*:*:*:*:system_center_operations_manager:*:*:*
Версия до 4.6 (включая)

EPSS

Процентиль: 54%
0.00316
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-203

Связанные уязвимости

github
больше 3 лет назад

A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.

EPSS

Процентиль: 54%
0.00316
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-203