CVE-2020-15302 affects Argent RecoveryManager versions prior to 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192. This vulnerability stems from a lack of signature requirements in the executeRecovery function for zero-guardian cases, allowing unauthenticated attackers to cause a denial of service (locking) or a full takeover. Rated 7.5 HIGH on CVSS, it is a network-exploitable vulnerability with low attack complexity and high impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0xdc350d09f71c48c5d22fbe2741e4d6a03970e192CPE matchmatch criteria | cpe:2.3:a:argent:recoverymanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.