PT-2020-20416 · Programi · Programi Bilanc
Georg Ph E Heise
·
Published
2020-12-19
·
Updated
2020-12-22
·
CVE-2020-8995
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Programi Bilanc Build 007 Release 014 31.01.2020
Description
The issue concerns hardcoded credentials in a .exe file supplied by Programi Bilanc, allowing remote attackers to gain access to the complete infrastructure, including the website, update server, and external issue tracking tools. This access could potentially lead to significant security breaches.
Recommendations
For Programi Bilanc Build 007 Release 014 31.01.2020, consider removing or securely storing the hardcoded credentials in the .exe file to prevent unauthorized access. As a temporary workaround, restrict access to the servers and infrastructure that use these credentials until a secure update is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Programi Bilanc