Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7q3-qpf8-7vp4

Опубликовано: 15 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 8.1

Описание

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.

EPSS

Процентиль: 14%
0.00047
Низкий

2.1 Low

CVSS4

8.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
nvd
10 месяцев назад

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.

EPSS

Процентиль: 14%
0.00047
Низкий

2.1 Low

CVSS4

8.1 High

CVSS3

Дефекты

CWE-295