CVE-2020-25966

HIGH

Sectona Spectra < 3.4.0 - Unauthenticated Sensitive Information Disclosure via SOAP API Endpoint

Title source: llm
STIX 2.1

Description

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
sectona/spectra < 3.4.0
Published Oct 28, 2020
Tracked Since Feb 18, 2026