CVE-2020-37135Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-06); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-07: 1Mentions · 2026-02-12: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-12: 102-0602-0702-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2020-37135 AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in w… https://www.cve.org/CVERecord?id=CVE-2020-37135

    Post summary

    The text announces CVE‑2020‑37135 as an authentication bypass in AMSS++ 4.7 that leverages hardcoded credentials, without mentioning patches, exploits, or active attacks.

    00010243
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2020-37135 (CVSS:9.3, HIGH) is Awaiting Analysis. AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using..https://nvd.nist.gov/vuln/detail/CVE-2020-37135 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A high‑severity authentication bypass vulnerability in AMSS++ 4.7 (CVE‑2020‑37135) has been reported and is currently awaiting analysis.

    0000057
    171 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2020-37135: AMSS++ 4.7 - Backdoor Admin Acco... Hardcoded admin password "1234" in AMSS++ 4.7 creates trivial network-level admin takeover with zero authentication com... https://zerodaysignal.com/vulnerability/CVE-2020-37135 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2020‑37135, describing a hardcoded admin password that permits trivial administrative takeover without authentication.

    0000096
    132 followersView on X

Explore more