CVE-2020-27199
Last modified
CVE-2020-27199 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. EPSS estimates a 2.88% chance of exploitation in the next 30 days.
Description
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Magic Home Pro Project | Magic Home Pro | 1.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27199?
How severe is CVE-2020-27199?
How do I fix CVE-2020-27199?
Are you affected by CVE-2020-27199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
