Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-37104

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2020-37104
  • Inextrix » Astpp » Version: 4.0.1
    cpe:2.3:a:inextrix:astpp:4.0.1


Contact Us

Shodan ® - All rights reserved