CVE-2020-36125: High severity paxstore vulnerability
Pax Technology PAXSTORE v7.0.820200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36125?
CVE-2020-36125 is considered to have a high severity due to the potential for unauthorized access to sensitive operations by authenticated attackers.
How do I fix CVE-2020-36125?
To fix CVE-2020-36125, upgrade your Pax Technology PAXSTORE software to a version higher than 7.0.8_20200511171508.
What kind of attacks can exploit CVE-2020-36125?
CVE-2020-36125 can be exploited by authenticated attackers to bypass password revalidation in sensitive operations.
Which versions of PAXSTORE are affected by CVE-2020-36125?
PAXSTORE versions 7.0.8_20200511171508 and lower are affected by CVE-2020-36125.
Who is impacted by CVE-2020-36125?
Any organization using affected versions of Pax Technology PAXSTORE is vulnerable to CVE-2020-36125 and at risk of unauthorized access.