CVE Vulnerabilities

CVE-2020-24029

Improper Authentication

Published: Sep 02, 2020 | Modified: Sep 10, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Qualiex Forlogic 1.0 (including) 1.0 (including)
Qualiex Forlogic 3.0 (including) 3.0 (including)

Potential Mitigations

References