Security readout for executives and security teams
Plain-English summary
IBM MaaS360 version 6.82 can be crashed by someone with physical access to the device. The crash may allow access to restricted applications and device settings. This is not a remote internet-scale issue, but it matters where MaaS360 enforces device restrictions on shared, frontline, or untrusted devices.
Executive priority
Treat this as a moderate-priority endpoint management issue. It is constrained by physical access, but it can undermine MaaS360 controls on affected devices. Remediate first where devices are shared, publicly accessible, or enforce important business restrictions.
Technical view
The CVSS 3.0 vector is AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, scoring 4.6. Sources describe a physical-access crash in IBM MaaS360 6.82 that may affect restriction enforcement. CVSS records high availability impact and no confidentiality or integrity impact, creating some impact ambiguity.
Likely exposure
Exposure is most likely on devices running IBM MaaS360 6.82, especially devices users or third parties can physically handle. Devices upgraded away from 6.82 or kept under strict physical control are less exposed based on the provided evidence.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation. CVSS exploit maturity is listed as unproven. The attack requires physical device access, low complexity, no privileges, and no user interaction according to the provided vector.
Researcher notes
Do not assume remote exploitability from the available evidence. The description mentions possible access to restricted apps and settings, while CVSS only scores availability impact. Validate against IBM guidance and affected MaaS360 6.82 deployments before expanding scope.
Mitigation direction
- Identify devices running IBM MaaS360 6.82.
- Review IBM advisory for the supported remediation path.
- Apply IBM-provided updates or configuration guidance.
- Reduce unsupervised physical access to affected devices.
- Prioritize shared or kiosk-like devices first.
Validation and detection
- Confirm MaaS360 client versions across managed devices.
- Verify no managed device remains on version 6.82.
- Review crash telemetry for MaaS360 app failures.
- Check whether restricted apps and settings remain blocked.
- Document physical-access assumptions for affected device groups.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-4353 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.6 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/PR:N/AC:L/AV:P/S:U/A:H/I:N/C:N/UI:N/RL:O/RC:C/E:U
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/PR:N/AC:L/AV:P/S:U/A:H/I:N/C:N/UI:N/RL:O/RC:C/E:U0.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
4.6MediumVector: CVSS:3.0/PR:N/AC:L/AV:P/S:U/A:H/I:N/C:N/UI:N/RL:O/RC:C/E:U
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ibm.com/support/pages/node/6151773CVE reference · x_refsource_CONFIRM
- ibm-maas360-cve20204353-dos (178505)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
