VulnerabilityModified
CVE-2020-13134
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS.
MEDIUM 4.8EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- tufin/securechange
- Source
- cve@mitre.org
References
- https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdThird Party Advisory
- https://portal.tufin.com/aspx/SecurityAdvisoriesPermissions Required
- https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdThird Party Advisory
- https://portal.tufin.com/aspx/SecurityAdvisoriesPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.