First published: Wed Dec 16 2020(Updated: )
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | <=10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14254.
The severity of CVE-2020-14254 is high with a score of 7.5.
HCL BigFix Inventory up to v10.0.2 is affected by CVE-2020-14254.
An attacker can passively record traffic and later decrypt it if TLS 2.0 and secure ciphers are not enabled.
Yes, an update to HCL BigFix Inventory version 10.0.3 or later fixes CVE-2020-14254. Review the provided reference for more information.