CVE-2020-24030 - CVE House
Back to Database
Status published Critical CVE-2020-24030

ForLogic Qualiex v1 and v3 has weak token expiration. This...

Vulnerability Description

ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-24030

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

qualiex
Vulnerable Versions:
1.0, 3.0

Timeline

Official Publish: September 2nd, 2020
Last Modified: October 14th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.