CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-10590

HIGH
7.5
CVSS Severity Score
EPSS Score0.1070%
EPSS Percentile1.75th
Published2021年7月30日
Last Modified2024年11月21日

Vulnerability Description

Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.

Affected Platforms (CPE)

📦
Replicated

Replicated Classic

>= 2.10.0 and <= 2.32.3
📦
Replicated

Replicated Classic

>= 2.33.0 and <= 2.36.0
📦
Replicated

Replicated Classic

>= 2.37.0 and <= 2.37.1
📦
Replicated

Replicated Classic

>= 2.38.0 and <= 2.38.5
📦
Replicated

Replicated Classic

>= 2.39.0 and <= 2.39.3
📦
Replicated

Replicated Classic

>= 2.40.0 and <= 2.40.3
📦
Replicated

Replicated Classic

>= 2.42.0 and <= 2.42.3
📦
Replicated

Replicated Classic

= 2.41.0

References & Advisories

関連する脆弱性情報