PT-2021-11921 · Pax Technology · Paxstore

Andriel C. S. Biagioni

+1

·

Published

2021-05-07

·

Updated

2021-05-13

·

CVE-2020-36127

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Pax Technology PAXSTORE versions 7.0.8 20200511171508 and lower
Description: The issue allows non-administrator users to access the replacement p12 certificate and its password, which is returned in base64. This occurs through the PUK signature functionality, where an administrator cannot view the current certificate password but can replace it. The replacement certificate and its password are accessible to non-administrator users.
Recommendations: For versions 7.0.8 20200511171508 and lower, consider restricting access to the PUK signature functionality to prevent non-administrator users from accessing the replacement p12 certificate and its password. As a temporary workaround, limit the use of the certificate replacement option until a fix is available.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36127

Affected Products

Paxstore