CVE-2020-16272: Input Validation
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-16272.
What is the severity of CVE-2020-16272?
The severity of CVE-2020-16272 is critical (9.1).
What is the affected software of CVE-2020-16272?
The affected software of CVE-2020-16272 is Kee Vault KeePassRPC before 1.12.0.
How can remote attackers exploit CVE-2020-16272?
Remote attackers can read and modify data in the KeePass database via an A=0 WebSocket connection.
Are there any references for CVE-2020-16272?
Yes, there are references available for CVE-2020-16272. Please refer to the following links: [Link 1](https://danzinger.wien/exploiting-keepassrpc/), [Link 2](https://forum.kee.pm/t/a-critical-security-update-for-keepassrpc-is-available/3040).