CVE-2013-511631.01.2020, 15:15Evernote prior to 5.5.1 has insecure password changeEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.1 HIGHLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NmitreCNA------CVEADP------Awaiting analysisThis vulnerability is currently awaiting analysis.Base ScoreCVSS 3.xEPSS ScorePercentile: 26%Common Weakness EnumerationCWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/89734https://packetstormsecurity.com/files/author/8433/https://www.securityfocus.com/bid/64320/infohttps://exchange.xforce.ibmcloud.com/vulnerabilities/89734https://packetstormsecurity.com/files/author/8433/https://www.securityfocus.com/bid/64320/info