// For flags

CVE-2020-5805

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.

En Marvell QConvergeConsole versiones anteriores a 5.5.0.74 incluyéndola, las credenciales son almacenadas en texto plano en el archivo tomcat-users.xml.&#xa0;Los usuarios OS-level en el host del componente QCC que no están autorizados para utilizar QCC pueden usar las credenciales de texto plano para iniciar sesión en el componente QCC

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-06 CVE Reserved
  • 2021-01-08 CVE Published
  • 2024-05-13 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-312: Cleartext Storage of Sensitive Information
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Marvell
Search vendor "Marvell"
Qconvergeconslole Gui
Search vendor "Marvell" for product "Qconvergeconslole Gui"
<= 5.5.0.74
Search vendor "Marvell" for product "Qconvergeconslole Gui" and version " <= 5.5.0.74"
-
Affected