CRITICAL

CVE-2020-14944

CVSS v3

9.8

CRITICAL

EPSS Score

11.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

Technical details

Published
6/22/2020

Frequently asked questions

What is CVE-2020-14944?

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

Is CVE-2020-14944 actively exploited?

Active exploitation of CVE-2020-14944 has not been confirmed. The EPSS score is 11.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-14944?

CVE-2020-14944 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-14944 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.