TLS-RSA Cipher Suite Vulnerability in HCL BigFix Inventory
CVE-2020-14254

7.5HIGH

Key Information:

Vendor
CVE Published:
16 December 2020

Summary

A vulnerability exists in HCL BigFix Inventory due to the use of outdated TLS-RSA cipher suites, which are not disabled in versions up to v10.0.2. If higher versions of the TLS protocol and secure cipher configurations are not enforced, this could allow an attacker to passively record the network traffic and potentially decrypt sensitive information at a later time. Organizations using these versions are strongly encouraged to implement the latest security configurations to mitigate risks associated with data exposure.

Affected Version(s)

HCL BigFix Inventory v9.x, v10.x

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.