CVE-2020-5684
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD
Description
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.
Affected (1)
Products: Nec: Ism Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.1 to 12.1 |
| Running on/with | Platform Versions |
|---|---|
Nec M120 | All versions |
Nec M12e | All versions |
Nec M320 | All versions |
Nec M320f | All versions |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.