8.8
CVSSv3

CVE-2020-25917

Published: 26/12/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Stratodesk NoTouch Center prior to 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

stratodesk notouch center

Exploits

Stratodesk NoTouch Center virtual appliance suffers from a privilege escalation vulnerability This was addressed in version 4468 ...