peter bassill · operator
$ cve CVE-2020-21994 JSON

CVE-2020-21994

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.66% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-522
On CISA KEVno
Public exploitnone known
Published2021-04-28
Last modified2026-06-17

Affected (13)

VendorProduct
ave53ab-wbs
ave53ab-wbs firmware
avedominaplus
avets01
avets01 firmware
avets03x-v
avets03x-v firmware
avets04x-v
avets04x-v firmware
avets05
avets05 firmware
avets05n-v
avets05n-v firmware

References

→ the Explorer  ·  watch your stack  ·  NVD