Insufficient Entropy in OTRS - CVE-2020-1773

 

Insufficient Entropy in OTRS - CVE-2020-1773

Published: March 27, 2020 / Updated: April 1, 2021


Vulnerability identifier: #VU51870
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1773
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.


Affected software

OTRS
otrs (Alpine package)

How to mitigate CVE-2020-1773

Install update from vendor's website.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins