Vulnerabilities > CVE-2020-28597 - Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Epignosishq Efront 5.2.17/5.2.21

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
epignosishq
CWE-335

Summary

A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.

Vulnerable Configurations

Part Description Count
Application
Epignosishq
2