Pyrescom Termod4 Time Management Devices: Sensitive Information Disclosure and Weak Encryption Vulnerability

Pyrescom Termod4 Time Management Devices: Sensitive Information Disclosure and Weak Encryption Vulnerability

CVE-2020-23162 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.

Learn more about our User Device Pen Test.