Verify Gateway
Vendor:
First CVE: Jul 22, 2020 · Active for 6 years
8
Total CVEs
More Total CVEs than 87% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Verify Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2020
6 years ago
Most Recent CVE
Jul 27, 2020
2,191 days ago
CVE Severity & Scoring
Verify Gateway8 CVEs
13%
50%
25%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (37.5%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (62.5%)
High0 (0.0%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-4400HIGH IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478. | Jul 22, 2020 | 7.5 | 26 | NO | NO |
CVE-2020-4372HIGH IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009 | Jul 22, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-4385CRITICAL IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound commun | Jul 22, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-4397MEDIUM IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 17 | Jul 22, 2020 | 5.9 | 21 | NO | NO |
CVE-2020-4369MEDIUM IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004. | Jul 22, 2020 | 5.5 | 20 | NO | NO |
CVE-2020-4405MEDIUM IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484. | Jul 27, 2020 | 4.3 | 18 | NO | NO |
CVE-2020-4399MEDIUM IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server. IBM X-Force ID: 179476. | Jul 22, 2020 | 6.5 | 17 | NO | NO |
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Forc | Jul 22, 2020 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Verify Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.1 | 8 | 6.3 | 0.8% | 0 | 0 |
| 1.0.0 | 8 | 6.3 | 0.8% | 0 | 0 |