Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7qc-57xc-5vrm

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.3

Описание

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.

EPSS

Процентиль: 0%
0.00007
Низкий

8.5 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 месяца назад

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.

EPSS

Процентиль: 0%
0.00007
Низкий

8.5 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-295