CVE-2020-7378 describes an unverified password change vulnerability in CRIXP OpenCRX versions 4.30 and 5.0-20200717 and prior. An unauthenticated attacker can exploit this flaw to change the password of any user, including administrative accounts, to an arbitrary value. This vulnerability is rated as CRITICAL with a CVSS score of 9.1, indicating a severe risk. Its attack vector is network-based with low attack complexity, requiring no user interaction, and leading to high impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Organizations using affected OpenCRX versions should upgrade to version 5.0-20200904 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.0CPE matchmatch criteria | cpe:2.3:a:opencrx:opencrx:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opencrx:opencrx:5.0:20200714:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opencrx:opencrx:5.0:20200715:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:opencrx:opencrx:5.0:20200717:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:opencrx:opencrx:5.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.