CVE-2020-24030
Last modified
CVE-2020-24030 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. EPSS estimates a 2.67% chance of exploitation in the next 30 days.
Description
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Forlogic | Qualiex | 1.0 |
| Forlogic | Qualiex | 3.0 |
References
- https://github.com/underprotection/CVE-2020-24030Third Party Advisory
- https://qualiex.comProduct, Vendor Advisory
- https://github.com/underprotection/CVE-2020-24030Third Party Advisory
- https://qualiex.comProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24030?
How severe is CVE-2020-24030?
How do I fix CVE-2020-24030?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-24020Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute…8.8
- CVE-2020-24025Certificate validation in node-sass 2.0.0 to 4.14.1 is disab…5.3
- CVE-2020-24026TinyShop, a free and open source mall based on RageFrame2, h…6.1
- CVE-2020-24027In Live Networks, Inc., liblivemedia version 20200625, there…9.8
- CVE-2020-24028ForLogic Qualiex v1 and v3 allows any authenticated customer…8.8
- CVE-2020-24029Because of unauthenticated password changes in ForLogic Qual…9.8
- CVE-2020-24032tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances…9.8
- CVE-2020-24033An issue was discovered in fs.com S3900 24T4S 1.7.0 and earl…8.8
- CVE-2020-24034Sagemcom F@ST 5280 routers using firmware version 1.150.61 h…8.8
- CVE-2020-24036PHP object injection in the Ajax endpoint of the backend in …8.8
- CVE-2020-24038myFax version 229 logs sensitive information in the export l…6.5
- CVE-2020-24045A sandbox escape issue was discovered in TitanHQ SpamTitan G…7.2
Are you affected by CVE-2020-24030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
