CVE-2020-4099

MEDIUM

HCL Verse < 12.0.15 - Inadequate Encryption Strength via Weak Key Length

Title source: llm
STIX 2.1

Description

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0027
EPSS Percentile 18.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326
Status published
Products (1)
hcltech/verse < 12.0.15
Published Nov 01, 2022
Tracked Since Feb 18, 2026