Vulnerability Details CVE-2020-12053
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-12053
-
cpe:2.3:a:unisys:stealth:3.4
-
cpe:2.3:a:unisys:stealth:3.4.108.0
-
cpe:2.3:a:unisys:stealth:3.4.209.0
-
cpe:2.3:a:unisys:stealth:4.0
-
cpe:2.3:a:unisys:stealth:4.0.027.0
-
cpe:2.3:a:unisys:stealth:4.0.114
-
cpe:2.3:a:unisys:stealth:4.0.131
-
cpe:2.3:a:unisys:stealth:4.0.134
-
cpe:2.3:a:unisys:stealth:5.0
-
cpe:2.3:a:unisys:stealth:5.0.024