Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3996

Опубликовано: 27 окт. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:afnetworking_project:afnetworking:*:*:*:*:*:*:*:*
Версия до 2.5.2 (включая)

EPSS

Процентиль: 37%
0.00158
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-254

Связанные уязвимости

debian
больше 10 лет назад

The default AFSecurityPolicy.validatesDomainName configuration for AFS ...

github
больше 3 лет назад

The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS

Процентиль: 37%
0.00158
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-254