PT-2020-14080 · Global Radar · Global Radar Bsa Radar

William Summerhill

·

Published

2020-06-22

·

Updated

2022-05-03

·

CVE-2020-14944

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Global RADAR BSA Radar versions 1.6.7234.24750 and earlier
Description The issue lacks valid authorization controls in multiple functions, which can allow for manipulation and takeover of user accounts if successfully exploited. The vulnerable functions exposed are: ChangePassword, SaveUserProfile, and GetUser.
Recommendations For Global RADAR BSA Radar versions 1.6.7234.24750 and earlier, consider disabling the ChangePassword, SaveUserProfile, and GetUser functions until a patch is available to prevent potential exploitation. Restrict access to these functions to minimize the risk of account manipulation and takeover.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14944

Affected Products

Global Radar Bsa Radar