CVE-2024-6890

Published Aug 7, 2024

Last updated 3 months ago

Overview

Description
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
Source
bbf0bd87-ece2-41be-b873-96928ee8fab9
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-798
bbf0bd87-ece2-41be-b873-96928ee8fab9
CWE-321

Social media

Hype score
Not currently trending

Configurations