Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h573-p6v2-3p2p

Опубликовано: 13 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 8.1

Описание

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

EPSS

Процентиль: 2%
0.00014
Низкий

7.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
nvd
4 месяца назад

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

CVSS3: 9.6
fstec
4 месяца назад

Уязвимость мобильных приложений TP-Link, связанная с некорректным подтверждением подлинности сертификата, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00014
Низкий

7.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-295