Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2996

Опубликовано: 01 сент. 2022
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python-scciclient_project:python-scciclient:0.11.0:*:*:*:*:python:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
redhat
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
debian
больше 3 лет назад

A flaw was found in the python-scciclient when making an HTTPS connect ...

CVSS3: 7.4
github
больше 3 лет назад

python-scciclient vulnerable to Man-in-the-middle (MITM) attacks

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3

Дефекты

CWE-295
CWE-295