{"api_version":"1","generated_at":"2026-07-23T23:23:40+00:00","cve":"CVE-2020-4099","urls":{"html":"https://cve.report/CVE-2020-4099","api":"https://cve.report/api/cve/CVE-2020-4099.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-4099","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-4099"},"summary":{"title":"CVE-2020-4099","description":"The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.","state":"PUBLIC","assigner":"psirt@hcl.com","published_at":"2022-11-01 18:15:00","updated_at":"2022-11-03 17:14:00"},"problem_types":["CWE-326"],"metrics":[],"references":[{"url":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100861","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Security Bulletin: HCL Verse for Android is susceptible to an APK signing key check vulnerability (CVE-2020-4099) - Customer Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-4099","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4099","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"4099","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hcltech","cpe5":"verse","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@hcl.com","DATE_PUBLIC":"2022-10-14T17:47:00.000Z","ID":"CVE-2020-4099","STATE":"PUBLIC","TITLE":"HCL Verse for Android is susceptible to an APK signing key check vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"HCL Verse for Android","version":{"version_data":[{"version_value":"< 12.0.15"}]}}]},"vendor_name":"HCL Software"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-326 Inadequate Encryption Strength"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100861","name":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100861"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-11-01 18:15:00","lastModifiedDate":"2022-11-03 17:14:00","problem_types":["CWE-326"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hcltech:verse:*:*:*:*:*:android:*:*","versionEndExcluding":"12.0.15","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"4099","Ordinal":"164123","Title":"CVE-2020-4099","CVE":"CVE-2020-4099","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"4099","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}