CVE-2020-10581

HIGH

Invigo Automatic Device Management < 5.0 - Unauthenticated Sensitive Data Exposure via Session Validity Check Issues

Title source: llm
STIX 2.1

Description

Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-668
Status published
Products (1)
invigo/automatic_device_management < 5.0
Published Mar 25, 2021
Tracked Since Feb 18, 2026