CVE-2020-29136: Medium severity cpanel vulnerability
Published Nov 27, 2020
·Updated
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
Affected Software
3 affected components
Cpanel Cpanel<11.86.0.32
Cpanel Cpanel>=11.90.0<11.90.0.17
Cpanel Cpanel>=11.92.0<11.92.0.2
Event History
Nov 27, 2020
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
Description
Frequently Asked Questions
1
What is CVE-2020-29136?
CVE-2020-29136 is a vulnerability in cPanel before version 90.0.17 that allows for 2FA bypass via a brute-force approach.
2
How does CVE-2020-29136 affect cPanel?
CVE-2020-29136 affects cPanel versions before 90.0.17 and allows for 2FA bypass via a brute-force approach.
3
What is the severity of CVE-2020-29136?
CVE-2020-29136 has a severity rating of 6.5 (medium).
4
How can CVE-2020-29136 be fixed?
To fix CVE-2020-29136, users should update their cPanel to version 90.0.17 or higher.
5
Where can I find more information about CVE-2020-29136?
You can find more information about CVE-2020-29136 in the cPanel documentation, the cPanel news announcement, and the Digital Defense news article.