TLS-RSA Cipher Suite Vulnerability in HCL BigFix Inventory
CVE-2020-14254
7.5HIGH
Summary
A vulnerability exists in HCL BigFix Inventory due to the use of outdated TLS-RSA cipher suites, which are not disabled in versions up to v10.0.2. If higher versions of the TLS protocol and secure cipher configurations are not enforced, this could allow an attacker to passively record the network traffic and potentially decrypt sensitive information at a later time. Organizations using these versions are strongly encouraged to implement the latest security configurations to mitigate risks associated with data exposure.
Affected Version(s)
HCL BigFix Inventory v9.x, v10.x
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved