PT-2020-16257 · Sectona · Sectona Spectra

Published

2020-10-28

·

Updated

2024-08-04

·

CVE-2020-25966

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sectona Spectra versions prior to 3.4.0
Description The issue concerns a vulnerable SOAP API endpoint that leaks sensitive information about configured assets without proper authentication. This could be exploited by unauthorized parties to obtain configured login credentials of the assets via a modified pAccountID value.
Recommendations For versions prior to 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable SOAP API endpoint to minimize the risk of exploitation. Avoid using the pAccountID value in the affected API endpoint until the issue is resolved.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-25966

Affected Products

Sectona Spectra