CVE-2020-14930

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:bt_ctroms_terminal_project:bt_ctroms_terminal:-:*:*:*:*:*:*:*

Information

Published : 2020-06-19 14:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-14930

Mitre link : CVE-2020-14930


JSON object : View

CWE
CWE-522

Insufficiently Protected Credentials

CWE-319

Cleartext Transmission of Sensitive Information

Advertisement

dedicated server usa

Products Affected

bt_ctroms_terminal_project

  • bt_ctroms_terminal