CVE-2020-35929

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
19/01/2021
Last modified:
29/01/2021

Description

In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kaspersky:tinycheck:*:*:*:*:*:*:*:* 2020-12-18 (excluding)