Authentication Bypass Vulnerability in Genexis Platinum-4410 Devices
CVE-2020-6170

9.8CRITICAL

Key Information:

Vendor

Genexis

Vendor
CVE Published:
8 January 2020

What is CVE-2020-6170?

The Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices are susceptible to an authentication bypass vulnerability. This flaw allows attackers to gain unauthorized access to sensitive information, specifically user credentials, embedded within the HTML source code of the device's web interface at the cgi-bin/index2.asp URI. As a result, attackers can exploit this vulnerability to obtain cleartext credentials, posing a significant risk to device security and user privacy.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-6170 : Authentication Bypass Vulnerability in Genexis Platinum-4410 Devices