Insufficient Entropy in OTRS - CVE-2020-1773

 

Insufficient Entropy in OTRS - CVE-2020-1773

Published: March 27, 2020 / Updated: April 1, 2021


Vulnerability identifier: #VU51870
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-1773
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: otrs.org
Affected software:
OTRS

Detailed vulnerability description

The vulnerability allows a remote authenticated user to read and manipulate data.

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.


How to mitigate CVE-2020-1773

Install update from vendor's website.

Sources