Описание
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00057
Низкий
2.2 Low
CVSS3
4.9 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-Other
Связанные уязвимости
CVSS3: 2.2
github
около 1 месяца назад
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
EPSS
Процентиль: 18%
0.00057
Низкий
2.2 Low
CVSS3
4.9 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-Other