CVE-2020-14254: High severity ibm bigfix platform vulnerability
Published Dec 16, 2020
·Updated
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
Affected Software
1 affected component
hcltech Bigfix Platform<=10.0.2
Remediation
Event History
Dec 16, 2020
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-14254.
2
What is the severity of CVE-2020-14254?
The severity of CVE-2020-14254 is high with a score of 7.5.
3
What software is affected by CVE-2020-14254?
HCL BigFix Inventory up to v10.0.2 is affected by CVE-2020-14254.
4
How can an attacker exploit CVE-2020-14254?
An attacker can passively record traffic and later decrypt it if TLS 2.0 and secure ciphers are not enabled.
5
Is there a fix for CVE-2020-14254?
Yes, an update to HCL BigFix Inventory version 10.0.3 or later fixes CVE-2020-14254. Review the provided reference for more information.