PT-2021-9152 · Psyprax · Psyprax

Eric Sesterhenn

·

Published

2021-02-05

·

Updated

2021-02-08

·

CVE-2020-10553

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Psyprax versions prior to 3.2.2
Description An issue was discovered where the file %PROGRAMDATA%Psyprax32PPScreen.ini contains a hash for the lockscreen of the application. If this entry is removed, the lockscreen is no longer displayed and the app is no longer locked. All local users are able to modify this file.
Recommendations For versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the %PROGRAMDATA%Psyprax32PPScreen.ini file to prevent local users from modifying it.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10553

Affected Products

Psyprax