PT-2021-11687 · Archery · Archery

Published

2021-01-29

·

Updated

2021-02-03

·

CVE-2020-29536

CVSS v3.1

4.3

Medium

VectorAC:L/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: Archer versions prior to 6.8 P2 (6.8.0.2)
Description: The issue allows a remote authenticated malicious attacker with access to service files to obtain sensitive information, which can be used in further attacks.
Recommendations: For versions prior to 6.8 P2 (6.8.0.2), update to version 6.8 P2 (6.8.0.2) or later to resolve the issue. As a temporary workaround, consider restricting access to service files to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29536

Affected Products

Archery