7.5
CVE-2020-10590
- EPSS 0.35%
- Veröffentlicht 30.07.2021 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Replicated ≫ Replicated Classic Version >= 2.10.0 <= 2.32.3
Replicated ≫ Replicated Classic Version >= 2.33.0 <= 2.36.0
Replicated ≫ Replicated Classic Version >= 2.37.0 <= 2.37.1
Replicated ≫ Replicated Classic Version >= 2.38.0 <= 2.38.5
Replicated ≫ Replicated Classic Version >= 2.39.0 <= 2.39.3
Replicated ≫ Replicated Classic Version >= 2.40.0 <= 2.40.3
Replicated ≫ Replicated Classic Version >= 2.42.0 <= 2.42.3
Replicated ≫ Replicated Classic Version2.41.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.567 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|