ZeroHour

CVE-2021-27756

CVSS 3.1
7.5 high
EPSS
<1%p45
Published
()
Modified
Description

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

Vendors
hcltech
Products
bigfix compliance
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.