CVE-2020-27199
Last modified
CVE-2020-27199 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. EPSS estimates a 2.88% chance of exploitation in the next 30 days.
Description
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Magic Home Pro Project | Magic Home Pro | 1.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27199?
How severe is CVE-2020-27199?
How do I fix CVE-2020-27199?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27192BinaryNights ForkLift 3.4 was compiled with the com.apple.se…7.8
- CVE-2020-27193A cross-site scripting (XSS) vulnerability in the Color Dial…6.1
- CVE-2020-27194An issue was discovered in the Linux kernel before 5.8.15. s…5.5
- CVE-2020-27195HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.1…9.1
- CVE-2020-27196An issue was discovered in PlayJava in Play Framework 2.6.0 …7.5
- CVE-2020-27197TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTA…9.8
- CVE-2020-2720Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…5.4
- CVE-2020-27207Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, rel…7.5
- CVE-2020-27208The flash read-out protection (RDP) level is not enforced du…6.8
- CVE-2020-27209The ECDSA operation of the micro-ecc library 1.0 is vulnerab…7.5
- CVE-2020-2721Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…6.5
- CVE-2020-27211Nordic Semiconductor nRF52840 devices through 2020-10-19 hav…5.7
Are you affected by CVE-2020-27199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
