Vulnerability Description
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Hcl Nomad | 1.0 |
Related Weaknesses (CWE)
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0078969Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0078969Vendor Advisory
FAQ
What is CVE-2020-4092?
CVE-2020-4092 is a vulnerability with a CVSS score of 5.3 (MEDIUM). "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting...
How severe is CVE-2020-4092?
CVE-2020-4092 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4092?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Hcl Nomad.