CVE Vulnerabilities

CVE-2020-24029

Improper Authentication

Published: Sep 02, 2020 | Modified: Oct 14, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Suppliers perspective is that this is corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Qualiex Forlogic 1.0 (including) 1.0 (including)
Qualiex Forlogic 3.0 (including) 3.0 (including)

Potential Mitigations

References