// For flags

CVE-2020-5684

 

Severity Score

4.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.

El cliente iSM desde versiones V5.1 anteriores a V12.1, que se ejecutan en NEC Storage Manager o NEC Storage Manager Express no verifican un certificado de servidor apropiadamente, el cual permite a un atacante de tipo man-in-the-middle espiar una comunicación cifrada o alterar la comunicación por medio de un certificado diseñado

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-06 CVE Reserved
  • 2020-12-24 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-295: Improper Certificate Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nec
Search vendor "Nec"
Ism Server
Search vendor "Nec" for product "Ism Server"
>= 5.1 < 12.1
Search vendor "Nec" for product "Ism Server" and version " >= 5.1 < 12.1"
-
Affected
in Nec
Search vendor "Nec"
M120
Search vendor "Nec" for product "M120"
--
Safe
Nec
Search vendor "Nec"
Ism Server
Search vendor "Nec" for product "Ism Server"
>= 5.1 < 12.1
Search vendor "Nec" for product "Ism Server" and version " >= 5.1 < 12.1"
-
Affected
in Nec
Search vendor "Nec"
M12e
Search vendor "Nec" for product "M12e"
--
Safe
Nec
Search vendor "Nec"
Ism Server
Search vendor "Nec" for product "Ism Server"
>= 5.1 < 12.1
Search vendor "Nec" for product "Ism Server" and version " >= 5.1 < 12.1"
-
Affected
in Nec
Search vendor "Nec"
M320
Search vendor "Nec" for product "M320"
--
Safe
Nec
Search vendor "Nec"
Ism Server
Search vendor "Nec" for product "Ism Server"
>= 5.1 < 12.1
Search vendor "Nec" for product "Ism Server" and version " >= 5.1 < 12.1"
-
Affected
in Nec
Search vendor "Nec"
M320f
Search vendor "Nec" for product "M320f"
--
Safe