Magento Mass Importer (aka MAGMI) versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure.
id: CVE-2020-5777
info:
name: Magento Mass Importer <0.7.24 - Remote Auth Bypass
author: dwisi
...