CVE-2020-28597 - CVE House
Back to Database
Status published Critical CVE-2020-28597

A predictable seed vulnerability exists in the password reset functionality...

Vulnerability Description

A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28597

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Epignosis
Vulnerable Versions:
Epignosis eFront LMS 5.2.17, Epignosis eFront LMS 5.2.21

Timeline

Official Publish: March 3rd, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.