CVE-2020-26868CWE-767

ARC Informatique PcVue Access to Critical Private Variable via Public Method

High · published October 12, 2020

CVSS v3.1
7.5
EPSS
2%
Percentile
80.9
In the wild
Unconfirmed
What it is

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.02151 · 80.9th percentile
Weakness
CWE-767 · Access to Critical Private Variable via Public Method
Published
2020-10-12T13:50Z
EPSS history
Timeline
  • 12 OCT 13:50Z
    ARC Informatique PcVue Access to Critical Private Variable via Public Method
    cvelistv5