VulnerabilityModified
CVE-2020-13461
The vendor has decided not to fix this vulnerability.
MEDIUM 4.3EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Affected
- tufin/securetrack
- Source
- cve@mitre.org
References
- https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdThird Party Advisory
- https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.