CVE-2020-2076
Last modified
CVE-2020-2076 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sick | Package Analytics | <= 04.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2076?
How severe is CVE-2020-2076?
How do I fix CVE-2020-2076?
Are you affected by CVE-2020-2076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
