PT-2020-14067 · Bt · Bt Ctroms Terminal Os Port Portal Ct-464

Akkus

+1

·

Published

2020-06-19

·

Updated

2021-07-21

·

CVE-2020-14930

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BT CTROMS Terminal OS Port Portal CT-464
Description An issue in the password-reset feature allows account takeover by disclosing the verification token. When a getverificationcode.jsp request is made, the token is sent not only to the user's registered phone number but also to the unauthenticated HTTP client.
Recommendations For BT CTROMS Terminal OS Port Portal CT-464, consider disabling the password-reset feature temporarily until a fix is available to prevent account takeover. Restrict access to the getverificationcode.jsp request to minimize the risk of exploitation.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14930

Affected Products

Bt Ctroms Terminal Os Port Portal Ct-464