CVE-2019-4576: IBM Qradar Network Packet Capture

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.

Affected products

  • IBM Qradar Network Packet Capture: from 7.3.0, before 7.3.2 (fixed in 7.3.2); version 7.3.2 only; version 7.3.3 only; version 7.4.0 only

Published 2020-06-10. Last modified 2026-06-17.