PT-2020-14080 · Global Radar · Global Radar Bsa Radar
William Summerhill
·
Published
2020-06-22
·
Updated
2022-05-03
·
CVE-2020-14944
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Global RADAR BSA Radar versions 1.6.7234.24750 and earlier
Description
The issue lacks valid authorization controls in multiple functions, which can allow for manipulation and takeover of user accounts if successfully exploited. The vulnerable functions exposed are: ChangePassword, SaveUserProfile, and GetUser.
Recommendations
For Global RADAR BSA Radar versions 1.6.7234.24750 and earlier, consider disabling the ChangePassword, SaveUserProfile, and GetUser functions until a patch is available to prevent potential exploitation. Restrict access to these functions to minimize the risk of account manipulation and takeover.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Global Radar Bsa Radar