// For flags

CVE-2020-7378

CRIXP OpenCRX Unverified Password Change

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020.

CRIXP OpenCRX versiones 4.30 y 5.0-20200717 y anteriores sufre de una vulnerabilidad de cambio de contraseña no verificada. Un atacante que es capaz de conectarse a la instancia de OpenCRX afectada puede cambiar la contraseña de cualquier usuario, incluyendo admin-Standard, para cualquier valor elegido. Este problema se resolvió en la versión 5.0-20200904, publicada el 4 de septiembre de 2020

*Credits: This issue was discovered and reported by Trevor Christiansen of Rapid7 in accordance with Rapid7's standard vulnerability disclosure policy.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-21 CVE Reserved
  • 2020-11-24 CVE Published
  • 2021-07-06 First Exploit
  • 2024-03-29 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
  • CWE-620: Unverified Password Change
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opencrx
Search vendor "Opencrx"
Opencrx
Search vendor "Opencrx" for product "Opencrx"
<= 4.3.0
Search vendor "Opencrx" for product "Opencrx" and version " <= 4.3.0"
-
Affected
Opencrx
Search vendor "Opencrx"
Opencrx
Search vendor "Opencrx" for product "Opencrx"
5.0
Search vendor "Opencrx" for product "Opencrx" and version "5.0"
20200714
Affected
Opencrx
Search vendor "Opencrx"
Opencrx
Search vendor "Opencrx" for product "Opencrx"
5.0
Search vendor "Opencrx" for product "Opencrx" and version "5.0"
20200715
Affected
Opencrx
Search vendor "Opencrx"
Opencrx
Search vendor "Opencrx" for product "Opencrx"
5.0
Search vendor "Opencrx" for product "Opencrx" and version "5.0"
20200717
Affected
Opencrx
Search vendor "Opencrx"
Opencrx
Search vendor "Opencrx" for product "Opencrx"
5.0.0
Search vendor "Opencrx" for product "Opencrx" and version "5.0.0"
-
Affected