PT-2020-14067 · Bt · Bt Ctroms Terminal Os Port Portal Ct-464
Akkus
+1
·
Published
2020-06-19
·
Updated
2021-07-21
·
CVE-2020-14930
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BT CTROMS Terminal OS Port Portal CT-464
Description
An issue in the password-reset feature allows account takeover by disclosing the verification token. When a getverificationcode.jsp request is made, the token is sent not only to the user's registered phone number but also to the unauthenticated HTTP client.
Recommendations
For BT CTROMS Terminal OS Port Portal CT-464, consider disabling the password-reset feature temporarily until a fix is available to prevent account takeover. Restrict access to the getverificationcode.jsp request to minimize the risk of exploitation.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bt Ctroms Terminal Os Port Portal Ct-464