← Back

CVE-2020-7378

nvd nist
Published: Nov 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020.

Affected (5)

Products: Opencrx: Opencrx
1 product
Opencrx
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Opencrx
Up to 4.3.0
Version 5.0.0
Version 5.0 20200714
Version 5.0 20200715
Version 5.0 20200717

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.