Show plain JSON{"id": "CVE-2020-4128", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}]}, "published": "2020-12-01T14:15:11.770", "references": [{"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085408", "tags": ["Patch", "Vendor Advisory"], "source": "psirt@hcl.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service."}, {"lang": "es", "value": "HCL Domino, es susceptible a una vulnerabilidad de omisi\u00f3n de pol\u00edticas de bloqueo en el servicio ID Vault. Un atacante no autenticado podr\u00eda usar esta vulnerabilidad para montar un ataque de fuerza bruta contra el servicio ID Vault"}], "lastModified": "2021-07-21T11:39:23.747", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E912DDC2-BF25-4D5D-B1AF-86742A4137B1", "versionEndIncluding": "9.0.1", "versionStartIncluding": "9.0.0"}, {"criteria": "cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDAF258F-BF11-4A8D-9211-BA6E79682BCA", "versionEndIncluding": "10.0.1", "versionStartIncluding": "10.0.0"}, {"criteria": "cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3A5C76D-53EC-49BA-A956-F2CF54F83661", "versionEndIncluding": "11.0.1", "versionStartIncluding": "11.0.0"}, {"criteria": "cpe:2.3:a:hcltech:domino:10.0.1:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC5EB2B8-9B48-4E9B-9726-71E4A6CCFA99"}, {"criteria": "cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10824FE5-1BCB-422A-8EFD-AE170C78FB43"}, {"criteria": "cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "985D72C3-3149-4DC1-85FA-C681CF779050"}, {"criteria": "cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8688C462-C24D-4E68-B2A1-488E20396DE5"}, {"criteria": "cpe:2.3:a:hcltech:domino:10.0.1:fix_pack_4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64D65B08-CAB2-4FC5-9261-4303EF796BCF"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@hcl.com"}