CVE-2020-21991
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
Published:Apr 28, 2021
Last Modified:Nov 21, 2024
EPS:Apr 28, 2021
EPSS Score:0.05284
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Ave
Product
53ab-wbs
Ave
53ab-wbs
Vendor
Ave
Product
53ab-wbs Firmware
Ave
53ab-wbs Firmware
Vendor
Ave
Product
Dominaplus
Ave
Dominaplus
Vendor
Ave
Product
Ts01
Ave
Ts01
Vendor
Ave
Product
Ts01 Firmware
Ave
Ts01 Firmware
Vendor
Ave
Product
Ts03x-v
Ave
Ts03x-v
Vendor
Ave
Product
Ts03x-v Firmware
Ave
Ts03x-v Firmware
Vendor
Ave
Product
Ts04x-v
Ave
Ts04x-v
Vendor
Ave
Product
Ts04x-v Firmware
Ave
Ts04x-v Firmware
Vendor
Ave
Product
Ts05
Ave
Ts05
Vendor
Ave
Product
Ts05 Firmware
Ave
Ts05 Firmware
Vendor
Ave
Product
Ts05n-v
Ave
Ts05n-v
Vendor
Ave
Product
Ts05n-v Firmware
Ave
Ts05n-v Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
