CVE-2021-27761: HCL BigFix Platform is affected by weak web transport security
Published May 6, 2022
·Updated
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
Affected Software
2 affected components
hcltech Bigfix Platform>=9.5<9.5.19
hcltech Bigfix Platform>=10.0<10.0.6
Event History
May 6, 2022
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27761?
CVE-2021-27761 refers to a vulnerability related to weak web transport security, specifically weak TLS, which allows an attacker to potentially decrypt data using various attack methods.
2
How severe is CVE-2021-27761?
CVE-2021-27761 has a severity rating of 7.5 (high).
3
Which software is affected by CVE-2021-27761?
Hcltech Bigfix Platform versions 9.5.0 to 9.5.19 and versions 10.0.0 to 10.0.6 are affected by CVE-2021-27761.
4
How can an attacker exploit CVE-2021-27761?
An attacker can potentially exploit CVE-2021-27761 by leveraging weak TLS to decrypt data through various attack techniques.
5
Is there a fix available for CVE-2021-27761?
Yes, it is recommended to update to a version of Hcltech Bigfix Platform that is not vulnerable to CVE-2021-27761.