Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-4095

Опубликовано: 16 июл. 2020
Источник: nvd
CVSS3: 6
CVSS2: 2.1
EPSS Низкий

Описание

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
Версия от 9.2 (включая) до 9.2.19 (включая)
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
Версия от 9.5 (включая) до 9.5.15 (включая)

EPSS

Процентиль: 7%
0.00026
Низкий

6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-312

Связанные уязвимости

github
больше 3 лет назад

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

EPSS

Процентиль: 7%
0.00026
Низкий

6 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-312