PT-2020-14860 · Keepass · Keepassrpc
Georg Merzdovnik
+2
·
Published
2020-08-03
·
Updated
2020-08-07
·
CVE-2020-16272
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
KeePassRPC versions prior to 1.12.0
Description
The issue concerns the SRP-6a implementation, which lacks validation for a client-provided parameter. This allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.
Recommendations
For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebSocket connection to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keepassrpc