PT-2022-9036 · Ibm · Ibm Siteprotector Appliance

Chris Shepherd

+8

·

Published

2022-07-11

·

Updated

2022-07-18

·

CVE-2020-4150

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM SiteProtector Appliance version 3.1.1
Description The issue concerns hard-coded credentials, such as a password or cryptographic key, used by the appliance for inbound authentication, outbound communication to external components, or encryption of internal data.
Recommendations For IBM SiteProtector Appliance version 3.1.1, consider changing the hard-coded credentials to unique, secure credentials to mitigate the risk of exploitation. As a temporary workaround, restrict access to the appliance until secure credentials can be implemented.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4150

Affected Products

Ibm Siteprotector Appliance