First published: Wed Jul 29 2020(Updated: )
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OpenClinic GA | =5.09.02 |
Update to version 5.89.05b or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14487 is considered a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2020-14487, ensure that the hidden default user account is explicitly disabled by an administrator.
CVE-2020-14487 affects OpenClinic GA version 5.09.02.
CVE-2020-14487 can facilitate unauthorized login and execution of arbitrary commands by attackers.
There is no specific patch mentioned for CVE-2020-14487, but disabling the default account mitigates the risk.