Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2020-25966
HistoryOct 28, 2020 - 5:37 p.m.

CVE-2020-25966

2020-10-2817:37:16
mitre
github.com
4
sectona spectra
soap api
sensitive information
authentication
unauthorized access
paccountid

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

69.6%

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

69.6%

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2020-25966