Описание
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Ссылки
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dell:secureworks:2.0.6:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 38%
0.00168
Низкий
6.8 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
CVSS3: 6.8
github
больше 3 лет назад
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
EPSS
Процентиль: 38%
0.00168
Низкий
6.8 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-310