4.4
CVE-2022-42451
- EPSS 0.15%
- Veröffentlicht 11.10.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 07:24:59
- Erkennungen
HCL BigFix Patch Management is vulnerable to insecurely stored credentials
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Bigfix Patch Management Version < 1055
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.045 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| CISA-ADP | 4.6 | 1.5 | 2.7 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
|
| psirt@hcl.com | 4.6 | 1.5 | 2.7 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108007