PT-2020-20416 · Programi · Programi Bilanc

Georg Ph E Heise

·

Published

2020-12-19

·

Updated

2020-12-22

·

CVE-2020-8995

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Programi Bilanc Build 007 Release 014 31.01.2020
Description The issue concerns hardcoded credentials in a .exe file supplied by Programi Bilanc, allowing remote attackers to gain access to the complete infrastructure, including the website, update server, and external issue tracking tools. This access could potentially lead to significant security breaches.
Recommendations For Programi Bilanc Build 007 Release 014 31.01.2020, consider removing or securely storing the hardcoded credentials in the .exe file to prevent unauthorized access. As a temporary workaround, restrict access to the servers and infrastructure that use these credentials until a secure update is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8995

Affected Products

Programi Bilanc