CVE-2020-24033
Last modified
CVE-2020-24033 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fs | S3900 24t4s Firmware | <= 1.7.0 |
References
- https://github.com/M0NsTeRRR/CVE-2020-24033Exploit, Third Party Advisory
- https://github.com/M0NsTeRRR/S3900-24T4S-CSRF-vulnerabilityExploit, Third Party Advisory
- https://github.com/M0NsTeRRR/CVE-2020-24033Exploit, Third Party Advisory
- https://github.com/M0NsTeRRR/S3900-24T4S-CSRF-vulnerabilityExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24033?
How severe is CVE-2020-24033?
How do I fix CVE-2020-24033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-24026TinyShop, a free and open source mall based on RageFrame2, h…6.1
- CVE-2020-24027In Live Networks, Inc., liblivemedia version 20200625, there…9.8
- CVE-2020-24028ForLogic Qualiex v1 and v3 allows any authenticated customer…8.8
- CVE-2020-24029Because of unauthenticated password changes in ForLogic Qual…9.8
- CVE-2020-24030ForLogic Qualiex v1 and v3 has weak token expiration. This a…9.8
- CVE-2020-24032tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances…9.8
- CVE-2020-24034Sagemcom F@ST 5280 routers using firmware version 1.150.61 h…8.8
- CVE-2020-24036PHP object injection in the Ajax endpoint of the backend in …8.8
- CVE-2020-24038myFax version 229 logs sensitive information in the export l…6.5
- CVE-2020-24045A sandbox escape issue was discovered in TitanHQ SpamTitan G…7.2
- CVE-2020-24046A sandbox escape issue was discovered in TitanHQ SpamTitan G…7.2
- CVE-2020-24051The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the…9.8
Are you affected by CVE-2020-24033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
