Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrrq-63xh-fccm

Опубликовано: 10 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.7
CVSS3: 5.7

Описание

MicroDicom DICOM Viewer version 2024.03

fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.

MicroDicom DICOM Viewer version 2024.03

fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.

EPSS

Процентиль: 4%
0.00019
Низкий

5.7 Medium

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.7
nvd
12 месяцев назад

MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.

EPSS

Процентиль: 4%
0.00019
Низкий

5.7 Medium

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-295