CVE-2020-4152Cleartext Transmission of Sensitive Info in IBM Qradar Network Security

Severity
5.9MEDIUMNVD
EPSS
0.1%
top 73.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 8
Latest updateMay 24

Description

IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/qradar_network_security5.4.0.05.4.0.14+1
CVEListV5ibm/qradar_network_security5.4.0, 5.5.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-98g9-rg6r-fh6r: IBM QRadar Network Security 52022-05-24
CVEList
CVE-2020-4152: IBM QRadar Network Security 52021-11-08

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - Win32k Elevation of Privilege2020-12-02
CVE-2020-4152 — IBM vulnerability | cvebase