CVE-2020-28206: Medium severity bitrix24 vulnerability
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28206?
CVE-2020-28206 is an "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability in Bitrix24 Bitrix Framework.
What is the severity of CVE-2020-28206?
The severity of CVE-2020-28206 is medium with a CVSS score of 6.5.
How does CVE-2020-28206 impact Bitrix24 Bitrix Framework?
CVE-2020-28206 allows a remote user to enumerate users in the administrator group and perform excessive authentication attempts on the admin login form in Bitrix24 Bitrix Framework.
What is the affected software version of CVE-2020-28206?
The affected software version of CVE-2020-28206 is Bitrix24 Bitrix Framework 20.0.
Is there a fix for CVE-2020-28206?
Yes, it is recommended to update to the latest version of Bitrix24 Bitrix Framework to fix CVE-2020-28206.