Описание
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:hcltech:icontrol:3.2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00097
Низкий
4.8 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 4.8
github
около 1 месяца назад
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.
EPSS
Процентиль: 1%
0.00097
Низкий
4.8 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-327