Improper Authorization in American Dynamics victor Web Client and Software House C•CURE Web Client - CVE-2020-9049
Published: November 18, 2020
Vulnerability identifier: #VU48520
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9049
CWE-ID: CWE-285
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to improper authorization check. A remote attacker on the local network can bypass access restrictions on the target system.
Affected software
American Dynamics victor Web Client
Software House C•CURE Web Client
Software House C•CURE Web Client
How to mitigate CVE-2020-9049
Install updates from vendor's website.
American Dynamics victor Web Client - update to 5.6 SP1
Software House C•CURE Web Client - addressed in versions 2.70_5.2_Update02, 2.80_v5.4.1_Update04, 2.90_Update01
Software House C•CURE Web Client - addressed in versions 2.70_5.2_Update02, 2.80_v5.4.1_Update04, 2.90_Update01