Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgxc-qhw9-rf7c

Опубликовано: 13 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.2
CVSS3: 5.9

Описание

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.

The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.

The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

EPSS

Процентиль: 9%
0.00188
Низкий

6.2 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.9
nvd
3 месяца назад

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information. The Prisma Access Agent on macOS, Windows, Linux and iOS are not affected.

CVSS3: 9.6
fstec
3 месяца назад

Уязвимость агента удаленного доступа пользователей к корпоративным ресурсам и приложениям Prisma Access Agent, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 9%
0.00188
Низкий

6.2 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-295