CVE-2020-2790: Medium severity mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 5.7.28 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2790?
CVE-2020-2790 is classified as a high severity vulnerability due to its ease of exploitation by low privileged attackers.
How do I fix CVE-2020-2790?
To fix CVE-2020-2790, update MySQL Server to version 5.7.29 or later.
What versions of MySQL are affected by CVE-2020-2790?
MySQL versions 5.7.28 and prior are affected by CVE-2020-2790.
Can CVE-2020-2790 be exploited remotely?
Yes, CVE-2020-2790 can be exploited remotely through multiple protocols by attackers with low privileges.
What components in MySQL does CVE-2020-2790 impact?
CVE-2020-2790 impacts the Pluggable Authentication component of the MySQL Server product.