CVE-2020-5684: Nec Ism Server
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.
Affected products
- Nec Ism Server: from 5.1, before 12.1 (fixed in 12.1)
Published 2020-12-24. Last modified 2026-06-17.