# CVE-2020-37135

## Summary

- **CVE ID:** CVE-2020-37135
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-798
- **Published:** Feb 6, 2026
- **Last Modified:** Mar 14, 2026

## Description

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

## Affected Products

- Amssplus — AMSS++ (4.7)

## References

- [CNA](https://www.exploit-db.com/exploits/48114)
- [CNA](https://www.vulncheck.com/advisories/amss-backdoor-admin-account)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.02%
- **EPSS Percentile:** 5.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._