Back to overview

CVE-2020-37168

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash comparison to iteratively test key candidates until discovering the correct production key, enabling them to forge valid payment signatures and manipulate transaction amounts.

Metadata

CVE ID
CVE-2020-37168
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-02-06 12:30 UTC
Published
2026-05-13 14:22 UTC
Last updated
2026-05-14 13:35 UTC
Primary CWE
CWE-328
Use of Weak Hash
Vendor / Product
Paiement / Ecommerce Systempay
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Paiement Ecommerce Systempay 1.0
Weakness (CWE)
CWESourceDescription
CWE-328 cna Use of Weak Hash
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview