{"api_version":"1","generated_at":"2026-07-23T12:33:14+00:00","cve":"CVE-2020-4042","urls":{"html":"https://cve.report/CVE-2020-4042","api":"https://cve.report/api/cve/CVE-2020-4042.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-4042","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-4042"},"summary":{"title":"CVE-2020-4042","description":"Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-07-10 20:15:00","updated_at":"2020-07-15 17:30:00"},"problem_types":["CWE-294"],"metrics":[],"references":[{"url":"https://github.com/bareos/bareos/security/advisories/GHSA-vqpj-2vhj-h752","name":"https://github.com/bareos/bareos/security/advisories/GHSA-vqpj-2vhj-h752","refsource":"CONFIRM","tags":["Mitigation","Third Party Advisory"],"title":"Authentication bypass in director when allowing client and director initiated connections · Advisory · bareos/bareos · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.bareos.org/view.php?id=1250","name":"https://bugs.bareos.org/view.php?id=1250","refsource":"MISC","tags":["Vendor Advisory"],"title":"0001250: Authentication bypass in Director when allowing client and director initiated connections - Bareos Bug Tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-4042","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4042","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"4042","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bareos","cpe5":"bareos","cpe6":"19.2.8","cpe7":"pre","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4042","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bareos","cpe5":"bareos","cpe6":"19.2.8","cpe7":"pre","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"4042","vulnerable":"1","versionEndIncluding":"19.2.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bareos","cpe5":"bareos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-4042","qid":"501528","title":"Alpine Linux Security Update for bareos"},{"cve":"CVE-2020-4042","qid":"504585","title":"Alpine Linux Security Update for bareos"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-4042","STATE":"PUBLIC","TITLE":"Authentication bypass in Bareos"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"bareos","version":{"version_data":[{"version_value":"< 19.2.8"}]}}]},"vendor_name":"bareos"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-294: Authentication Bypass by Capture-replay"}]}]},"references":{"reference_data":[{"name":"https://github.com/bareos/bareos/security/advisories/GHSA-vqpj-2vhj-h752","refsource":"CONFIRM","url":"https://github.com/bareos/bareos/security/advisories/GHSA-vqpj-2vhj-h752"},{"name":"https://bugs.bareos.org/view.php?id=1250","refsource":"MISC","url":"https://bugs.bareos.org/view.php?id=1250"}]},"source":{"advisory":"GHSA-vqpj-2vhj-h752","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-07-10 20:15:00","lastModifiedDate":"2020-07-15 17:30:00","problem_types":["CWE-294"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bareos:bareos:19.2.8:pre:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bareos:bareos:*:*:*:*:*:*:*:*","versionEndIncluding":"19.2.7","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"4042","Ordinal":"164035","Title":"CVE-2020-4042","CVE":"CVE-2020-4042","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"4042","Ordinal":"1","NoteData":"Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to the director itself leading to the director responding to the replayed challenge. The response obtained is then a valid reply to the directors original challenge. This is fixed in version 19.2.8.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"4042","Ordinal":"2","NoteData":"2020-07-10","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"4042","Ordinal":"3","NoteData":"2020-07-10","Type":"Other","Title":"Modified"}]}}}