VulnerabilityModified
CVE-2016-2951
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
LOW 3.7EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- ibm/bigfix remote control
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89785Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21991885Vendor Advisory
- http://www.securityfocus.com/bid/94601
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89785Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21991885Vendor Advisory
- http://www.securityfocus.com/bid/94601
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.