CVE-2020-4095 Information
Feb 14, 2021
cve
Description
\BigFix Platform is storing clear text credentials within the system’s memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments limiting administrative access.\
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Reference
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080772
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.0
Share on: