HIGH🇵🇱 Wersja polska

CVE-2021-27756

CVSS 7.5v3.1pub. 2022-03-04upd. 2024-11-21

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Hcltech Bigfix Compliance

    APP
    Hcltech
    2.0 – 2.0.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-37525MEDIUM5.3same product

Wrażliwe ujawnienie informacji w HCL BigFix Compliance umożliwia zdalnemu atakującemu dostęp do plików w katal...

CVE-2024-42213MEDIUM5.3same product

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An atta...

CVE-2024-42212MEDIUM5.4same product

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site R...

CVE-2024-30140MEDIUM5.4same product

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated b...

CVE-2024-30141MEDIUM4.7same product

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Det...