CVE-2016-2951
LOWIBM BigFix Remote Control < 9.1.2 - Weak Encryption Strength
Title source: llmDescription
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21991885
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89785
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/94601
Scores
CVSS v3
3.7
EPSS
0.0066
EPSS Percentile
47.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-310
Status
published
Products (1)
ibm/bigfix_remote_control
< 9.1.2
Published
Nov 30, 2016
Tracked Since
Feb 18, 2026