Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5777

53
FAUCET Score

CVE-2020-5777 describes a critical remote authentication bypass vulnerability affecting MAGMI versions prior to 0.7.24. This flaw allows an unauthenticated attacker to gain access by exploiting a database connection failure, which can be triggered by overwhelming the MySQL server with simultaneous requests. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed in KEV, exploit intelligence indicates public Nuclei templates exist, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.7.24CPE matchmatch criteria
cpe:2.3:a:magmi_project:magmi:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
23.30%
Probability of exploitation in next 30 days
EPSS Percentile
97.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2020-5777 · Sep 4, 2020
This CVE's current EPSS score of 0.2330 is in the 94th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

composerpatch availablevia ghsa
Product: dweeves/magmiFixed in: 0.7.24
esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (8)

composerGHSA-g475-pch5-6wvvcritical

Authentication bypass in MAGMI

May 6, 2021
twiliollm-twilio-c523158f6823ea6eMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
esetllm-eset-2cca93142aaba91aMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
hyperledgerllm-hyperledger-7abed9465eeee0f9MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
pnpmllm-pnpm-648706aff9b8cfeeMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
omronllm-omron-c17b909bb3f34c5dMEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
openrefinellm-openrefine-261598723f4c2e00MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020
mariadbllm-mariadb-d1ea3e268315b8e0MEDIUM

MAGMI Multiple Vulnerabilities

Sep 1, 2020

References

tenable.com / security/research/tra-2020-51
Third Party Advisory