CVE-2020-13793: Critical severity ivanti dsm vulnerability
Published Aug 6, 2020
·Updated
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
Affected Software
1 affected component
Ivanti DSM netinst=5.1
Event History
Aug 6, 2020
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13793?
CVE-2020-13793 is rated as high severity due to the potential for unauthorized access to sensitive Active Directory credentials.
2
How do I fix CVE-2020-13793?
To fix CVE-2020-13793, upgrade to a version of Ivanti DSM netinst that does not use a static hard-coded encryption key for storing AD credentials.
3
What are the risks associated with CVE-2020-13793?
The risks associated with CVE-2020-13793 include unauthorized access to sensitive AD credentials, leading to potential data breaches or network compromise.
4
Which version of Ivanti DSM netinst is affected by CVE-2020-13793?
CVE-2020-13793 specifically affects Ivanti DSM netinst version 5.1.
5
Is there a workaround for CVE-2020-13793?
There is no known workaround for CVE-2020-13793; upgrading to a secure version is the recommended action.