7.5
CVSSv3

CVE-2020-12712

Published: 11/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows malicious users to decrypt the user/password that is optionally stored with a user's profile.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sos-berlin jobscheduler

Exploits

SOS JobScheduler version 1133 encrypts a secret by simply using the name of a profile as the key, making it trivial to decrypt ...

Github Repositories

Description and public exploit for CVE-2020-12712

CVE-2020-12712: SOS JobScheduler decryption of stored password The script in this repository allows you to decrypt the password(s) stored in the (S)FTP configuration file for a JobScheduler instance Description SOS JobScheduler is a tool for remote system administration that allows users to call maintenance scripts via a web interface The tool places the maintenance scripts o