Back to overview

CVE-2020-9045

CRITICAL
9.9
CVSS 3.1
Description
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.

Metadata

CVE ID
CVE-2020-9045
State
PUBLISHED
Assigner
jci
Reserved
2020-02-18 00:00 UTC
Published
2020-05-21 14:45 UTC
Last updated
2024-08-04 10:19 UTC
Primary CWE
CWE-312
CWE-312 - Cleartext Storage of Sensitive Information
Vendor / Product
Johnson Controls / Software House C•CURE 9000 v2.70
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Johnson Controls American Dynamics victor Video Management System v5.2 5.2
Johnson Controls Software House C•CURE 9000 v2.70 2.70
Weakness (CWE)
CWESourceDescription
CWE-312 cna CWE-312 - Cleartext Storage of Sensitive Information
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview