First published: Thu Aug 06 2020(Updated: )
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti DSM netinst | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13793 is rated as high severity due to the potential for unauthorized access to sensitive Active Directory credentials.
To fix CVE-2020-13793, upgrade to a version of Ivanti DSM netinst that does not use a static hard-coded encryption key for storing AD credentials.
The risks associated with CVE-2020-13793 include unauthorized access to sensitive AD credentials, leading to potential data breaches or network compromise.
CVE-2020-13793 specifically affects Ivanti DSM netinst version 5.1.
There is no known workaround for CVE-2020-13793; upgrading to a secure version is the recommended action.