Medium severity4.8NVD Advisory· Published Dec 24, 2020· Updated Jun 17, 2026
CVE-2020-5684
CVE-2020-5684
Description
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <12.1
- NEC Corporation/Management software for NEC Storage disk array systemv5Range: iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express
Patches
Vulnerability mechanics
References
2- jpn.nec.com/security-info/secinfo/nv20-015.htmlnvdVendor Advisory
- jvn.jp/en/jp/JVN10100024/index.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.