Vulnerability Description
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker retrieves all passwords from another systems, available for affected account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clickstudios | Passwordstate | 8.9 |
Related Weaknesses (CWE)
References
- https://github.com/jet-pentest/CVE-2020-27747Third Party Advisory
- https://www.clickstudios.com.au/ProductVendor Advisory
- https://github.com/jet-pentest/CVE-2020-27747Third Party Advisory
- https://www.clickstudios.com.au/ProductVendor Advisory
FAQ
What is CVE-2020-27747?
CVE-2020-27747 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digi...
How severe is CVE-2020-27747?
CVE-2020-27747 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27747?
Check the references section above for vendor advisories and patch information. Affected products include: Clickstudios Passwordstate.