CVE-2020-27747 describes a brute-force vulnerability in Click Studios Passwordstate 8.9 (Build 8973). If a user has configured a 4-digit PIN for mobile access, a remote attacker can exploit this weakness to brute-force the PIN, potentially gaining access to all passwords associated with the compromised account. This vulnerability carries a CVSS score of 6.8 (Medium), indicating a low attack complexity with high confidentiality, integrity, and availability impacts, though it requires physical access (AV:P). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.9CPE matchmatch criteria | cpe:2.3:a:clickstudios:passwordstate:8.9:build_8973:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.