PT-2020-15619 · Umanni · Umanni Rh

Inflixim4Be

·

Published

2020-08-26

·

Updated

2021-07-21

·

CVE-2020-24008

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Umanni RH version 1.0
Description The issue is related to user enumeration during password recovery. It allows an attacker to determine if a user is valid or not based on differences in messages, potentially enabling a brute force attack with valid users.
Recommendations For Umanni RH version 1.0, consider modifying the password recovery mechanism to return generic messages for all attempts, regardless of the user's validity, to prevent user enumeration. As a temporary workaround, restrict access to the password recovery feature until a more robust solution is implemented.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24008

Affected Products

Umanni Rh