PT-2020-16440 · Damstra · Damstra Smart Asset

Published

2020-10-02

·

Updated

2020-10-06

·

CVE-2020-26526

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Damstra Smart Asset version 2020.7
Description An issue was discovered in the login page of the affected software, allowing enumeration of valid usernames. The application sends different server responses when the username is invalid versus when it is valid, with messages "Unable to find an APIDomain" for invalid usernames and "Wrong email or password" for valid ones.
Recommendations For Damstra Smart Asset version 2020.7, consider modifying the login page to return a generic error message for both valid and invalid usernames to prevent enumeration. As a temporary workaround, restrict access to the login page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-26526

Affected Products

Damstra Smart Asset