MEDIUM · 6.5

CVE-2020-24038

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

Vulnerability Description

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
EramMyfax150 Firmware229
EramMyfax150-
EramMyfax250 Firmware229
EramMyfax250-
EramMyfax450 Firmware229
EramMyfax450-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24038?

CVE-2020-24038 is a vulnerability with a CVSS score of 6.5 (MEDIUM). myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

How severe is CVE-2020-24038?

CVE-2020-24038 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24038?

Check the references section above for vendor advisories and patch information. Affected products include: Eram Myfax150 Firmware, Eram Myfax150, Eram Myfax250 Firmware, Eram Myfax250, Eram Myfax450 Firmware.