Back to search
CVE-2020-4095
Published: Jul 16, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
| Vendor | Product | Versions |
|---|---|---|
n/a | "HCL BigFix Platform" | affected "v9.2 - 9.2.19, v9.5 - 9.5.15" |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now