CVE-2020-4042 is a medium-severity authentication bypass vulnerability affecting Bareos versions prior to 19.2.8. A malicious client can exploit this flaw by replaying the director's cram-md5 challenge back to itself, thereby tricking the director into providing a valid response without knowing the shared secret, provided the director allows client-initiated connections. The attack vector is network-based with high attack complexity, potentially leading to high integrity impact but no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.2.7CPE matchmatch criteria | cpe:2.3:a:bareos:bareos:*:*:*:*:*:*:*:* | ||
19.2.8CPE matchmatch criteria | cpe:2.3:a:bareos:bareos:19.2.8:pre:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.