First published: Sun Jul 10 2022(Updated: )
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SiteProtector system | =3.1.1 | |
IBM Security SiteProtector System | <=3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4150 has a high severity due to hard-coded credentials that can be exploited for unauthorized access.
To mitigate CVE-2020-4150, users should update their IBM SiteProtector Appliance to the latest version that resolves hard-coded credential issues.
The risks of CVE-2020-4150 include potential unauthorized access to the system and compromised data confidentiality.
CVE-2020-4150 affects IBM Security SiteProtector System version 3.1.1 and earlier.
Yes, IBM provides a patch for CVE-2020-4150 in the latest version of the SiteProtector Appliance.