PT-2021-10709 · Unknown · Ave Dominaplus

Gjoko Krstic

·

Published

2021-04-28

·

Updated

2022-10-26

·

CVE-2020-21994

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AVE DOMINAplus versions prior to 1.11
Description: The issue allows an unauthenticated attacker to obtain administrative login information by accessing an unprotected directory that hosts an XML file '/xml/authClients.xml', enabling a successful authentication bypass attack.
Recommendations: For versions prior to 1.11, restrict access to the '/xml/authClients.xml' file to prevent unauthorized disclosure of administrative login information. Consider protecting the directory that hosts this file to mitigate the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-21994

Affected Products

Ave Dominaplus