SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24038

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

MEDIUM 6.5EPSS 1.12%

Does this matter?

Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.

Description

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.12% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
eram/myfax150 firmware · eram/myfax250 firmware · eram/myfax450 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.