CVE-2020-14930
CTROMS Terminal OS Port Portal - 'Password Reset' Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.
Se detectó un problema en BT CTROMS Terminal OS Port Portal CT-464. Una toma de control de la cuenta puede presentarse porque la funcionalidad password-reset revela el token de verificación. Tras una petición del archivo getverificationcode.jsp, este token se transmite no solo al número de teléfono registrado de la cuenta de usuario, sino que también se transmitía al cliente HTTP no autenticado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-06-19 CVE Reserved
- 2020-06-19 CVE Published
- 2024-04-08 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/48196 | 2024-08-04 | |
https://www.pentest.com.tr/exploits/CTROMS-Terminal-OS-Port-Portal-Password-Reset-Authentication-Bypass.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bt Ctroms Terminal Project Search vendor "Bt Ctroms Terminal Project" | Bt Ctroms Terminal Search vendor "Bt Ctroms Terminal Project" for product "Bt Ctroms Terminal" | - | - |
Affected
|