« Volver al listado

CVE-2020-13134

Estado: ModificadaMedia (4.8)—

Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13134",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-20T02:15:13.037",
  "references": [
    {
      "url": "https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://portal.tufin.com/aspx/SecurityAdvisories",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://portal.tufin.com/aspx/SecurityAdvisories",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1."
    },
    {
      "lang": "es",
      "value": "Tufin SecureChange versiones anteriores a R19.3 HF3 y R20-1 HF1, son vulnerables a un ataque de tipo XSS almacenado. La explotación con éxito requiere privilegios de administrador (para almacenar la carga útil XSS en sí) y puede explotar (ser desencadena por) usuarios administradores. Todas las versiones de TOS con implementaciones de SecureChange versiones anteriores a R19.3 HF3 y R20-1 HF1 están afectadas. Unas vulnerabilidades son corregidas en versiones R19.3 HF3 y R20-1 HF1"
    }
  ],
  "lastModified": "2026-06-17T02:52:40.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tufin:securechange:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69386FD3-01E9-407B-BB7A-7F0D55702FF8",
              "versionEndExcluding": "r19-3"
            },
            {
              "criteria": "cpe:2.3:a:tufin:securechange:r19-3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FBF2A72-1FF7-4061-95E9-FA347CB0E492"
            },
            {
              "criteria": "cpe:2.3:a:tufin:securechange:r20-1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFFC335B-1334-43E9-A7C4-077E65137A25"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}