CVE Database
/

CVE-2020-4095

Back to search

CVE-2020-4095

Published: Jul 16, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

VendorProductVersions

n/a

"HCL BigFix Platform"

affected
"v9.2 - 9.2.19, v9.5 - 9.5.15"

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now