ZeroHour

CVE-2020-14254

CVSS 3.1
7.5 high
EPSS
<1%p49
Published
()
Modified
Description

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

Vendors
hcltech
Products
bigfix platform
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.