ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-25565”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-25565
Published
2021-08-11
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions and execute code on the server.