ZeroHour

CVE-2020-9049

CVSS 3.1
5.3 medium
EPSS
<1%p43
Published
()
Modified
Description

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.

Vendors
johnsoncontrols
Products
c-cure web, victor web
Weakness
CWE-285, CWE-287
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.