CVE-2020-7378
Summary
| CVE | CVE-2020-7378 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-24 17:15:00 UTC |
| Updated | 2020-12-07 21:26:00 UTC |
| Description | CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Opencrx | Opencrx | 5.0 | 20200714 | All | All |
| Application | Opencrx | Opencrx | 5.0 | 20200715 | All | All |
| Application | Opencrx | Opencrx | 5.0 | 20200717 | All | All |
| Application | Opencrx | Opencrx | 5.0.0 | All | All | All |
| Application | Opencrx | Opencrx | 5.0 | 20200714 | All | All |
| Application | Opencrx | Opencrx | 5.0 | 20200715 | All | All |
| Application | Opencrx | Opencrx | 5.0 | 20200717 | All | All |
| Application | Opencrx | Opencrx | 5.0.0 | All | All | All |
| Application | Opencrx | Opencrx | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-7378: OpenCRX Unverified Password Change (FIXED) | MISC | blog.rapid7.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was discovered and reported by Trevor Christiansen of Rapid7 in accordance with Rapid7's standard vulnerability disclosure policy.
There are currently no legacy QID mappings associated with this CVE.