ZeroHour

CVE-2020-11658

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

Vendors
broadcom
Products
ca api developer portal
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.