Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administrators). Version 5.20 of MegaBIP fixes this issue.
Tokens used for password resets are generated using limited randomness space and a value that an attacker can independently query. Knowing a user's login, an attacker can use brute force to guess the valid password reset token. After guessing the token, it is possible to set a new password for the victim's account without any authorization.
An attacker can take control of any user account in the MegaBIP system, including administrator accounts, leading to complete breach of confidentiality and integrity of data managed in the system.
MegaBIP software should be updated to version 5.20, which eliminates the described vulnerability. Patches and details are available from the manufacturer at megabip.pl.
MegaBIP software in versions prior to 5.20
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X