Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-9045 |
CWE-ID | CWE-312 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
American Dynamics victor Video Management System Other software / Other software solutions Software House C•CURE 9000 Client/Desktop applications / Antivirus software/Personal firewalls |
Vendor | Johnson Controls |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU28179
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-9045
CWE-ID:
CWE-312 - Cleartext Storage of Sensitive Information
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to view the password on the target system.
The vulnerability exists due to the credentials of the user performing the installation or upgrade are saved in a file. A remote authenticated attacker can obtain this credential because the install log file persists after the installation.
MitigationInstall updates from vendor's website.
Vulnerable software versionsAmerican Dynamics victor Video Management System: 5.2
Software House C•CURE 9000: 2.70
CPE2.3 External linkshttp://www.johnsoncontrols.com/cyber-solutions/security-advisories
http://www.us-cert.gov/ics/advisories/ICSA-20-142-01
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?