Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfvg-p8x9-f25q

Опубликовано: 22 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.

EPSS

Процентиль: 5%
0.00022
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
nvd
18 дней назад

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.

EPSS

Процентиль: 5%
0.00022
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295