Описание
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encrypted connections to cleartext.
Ссылки
- MitigationThird Party Advisory
- MitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.2.1.0 (исключая)
cpe:2.3:a:cordaware:bestinformed:*:*:*:*:*:windows:*:*
EPSS
Процентиль: 49%
0.00258
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encrypted connections to cleartext.
EPSS
Процентиль: 49%
0.00258
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-295