CVE-2020-12053

CRITICAL

Unisys Stealth 3.4.x-5.x < 5.0.026 - Incorrect Authorization via Certificate-Based Endpoint

Title source: llm
STIX 2.1

Description

In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0068
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
unisys/stealth 3.4 - 5.0.026
Published Jun 22, 2020
Tracked Since Feb 18, 2026