CVE-2020-14494 PUBLISHED CVSS 9.199999809265137 CRITICAL

OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.

EPSS 0.21% · 43.8th percentile

Risk Scores

CVSS v4.0
9.199999809265137
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.21%
43.8th percentile

Affected Products

VendorProductVersions
n/aOpenClinic GAVersions 5.09.02 and 5.89.05b
openclinic_ga_projectopenclinic_ga5.09.02, 5.89.05b

Timeline

References

Open in Interactive Console →