CVE-2020-25966
Last modified
CVE-2020-25966 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sectona | Spectra | < 3.4.0 |
References
- https://gitlab.com/Gazzaz/Spectra_API_Issue/Exploit, Third Party Advisory
- https://gitlab.com/Gazzaz/Spectra_API_Issue/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25966?
How severe is CVE-2020-25966?
How do I fix CVE-2020-25966?
Are you affected by CVE-2020-25966?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
