CVE-2020-28597
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2021
Last modified:
31/08/2022
Description
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:epignosishq:efront:5.2.17:*:*:*:pro:*:*:* | ||
| cpe:2.3:a:epignosishq:efront:5.2.21:*:*:*:pro:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



