CVE-2020-37168 - CVE House
Back to Database
Status published Critical CVE-2020-37168

Ecommerce Systempay 1.0 Production Key Brute Force

Vulnerability Description

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash comparison to iteratively test key candidates until discovering the correct production key, enabling them to forge valid payment signatures and manipulate transaction amounts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37168

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • live3

Affected Vendor

Affected Software

Ecommerce Systempay
Vulnerable Versions:
1.0

Timeline

Official Publish: May 13th, 2026
Last Modified: May 14th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.