CVE-2020-15367 affects Venki Supravizio BPM 10.1.2, stemming from a lack of authentication attempt limits, enabling unauthenticated brute-force attacks against the login page. This vulnerability is rated as Critical (CVSS 9.8), indicating a high potential for complete compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction required. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) has been identified, and community discussion is minimal, the high FAUCET Risk Score of 82/100 suggests a significant inherent risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.2CPE matchmatch criteria | cpe:2.3:a:venki:supravizio_bpm:10.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.