← console
voxell vciy

CVE-2020-11862: Insecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account Manager

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to netiq privileged account manager 3.7.0.2 or later upper bounds of the CVE record's affected ranges
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2.

weakness
CWE-770 Allocation of Resources Without Limits or Throttling
affected
OpenText NetIQ Privileged Account Manager
published ranges
opentext netiq privileged account manager < 3.7.0.2
first unaffected version, by branch
netiq privileged account manager 3.7.0.2
severity
8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
assigned by
OpenText
published
2024-03-13

check us netiq.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
14 Mar 20240.00043
17 Mar 20250.00196scoring model v2025.03.14
29 Mar 20250.00222
30 Mar 20250.00196
21 Apr 20250.00254
22 Apr 20250.00221
28 Apr 20250.00169
18 Nov 20250.00271
21 Nov 20250.00169
15 Jun 20260.007scoring model v2026.06.15

10 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.01 on 2026-06-15 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: netiq privileged account manager 3.7.0.2 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2020-11862', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.