Lucene search

K
cvelistMitreCVELIST:CVE-2020-35584
HistoryDec 23, 2020 - 2:53 p.m.

CVE-2020-35584

2020-12-2314:53:19
mitre
www.cve.org
3
solstice pod
web services
unencrypted channels
browser look-in
attacker
network traffic
interactions
administrator passwords
screen keys

AI Score

5.6

Confidence

High

EPSS

0.002

Percentile

61.4%

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user’s network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

AI Score

5.6

Confidence

High

EPSS

0.002

Percentile

61.4%

Related for CVELIST:CVE-2020-35584