Vulnerability Description
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freemedsoftware | Openclinic Ga | 5.09.02 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-14487?
CVE-2020-14487 is a vulnerability with a CVSS score of 9.4 (CRITICAL). OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitr...
How severe is CVE-2020-14487?
CVE-2020-14487 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-14487?
Check the references section above for vendor advisories and patch information. Affected products include: Freemedsoftware Openclinic Ga.