Описание
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.6 (исключая)
cpe:2.3:a:norton:install_norton_security:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 46%
0.0023
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 3.7
github
больше 3 лет назад
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
EPSS
Процентиль: 46%
0.0023
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-295