Lucene search

K
cve[email protected]CVE-2020-4095
HistoryJul 16, 2020 - 7:15 p.m.

CVE-2020-4095

2020-07-1619:15:12
CWE-312
CWE-522
web.nvd.nist.gov
37
bigfix
platform
credentials
clear text
memory
privilege escalation
nvd
cve-2020-4095

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

“BigFix Platform is storing clear text credentials within the system’s memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access.”

Affected configurations

NVD
Node
hcltechbigfix_platformRange9.29.2.19
OR
hcltechbigfix_platformRange9.59.5.15

CNA Affected

[
  {
    "product": "\"HCL BigFix Platform\"",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "\"v9.2 - 9.2.19, v9.5 - 9.5.15\""
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Related for CVE-2020-4095