Описание
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 24.9.0 (включая) до 25.2.0 (исключая)
cpe:2.3:a:altium:designer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00174
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 5.3
github
7 месяцев назад
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.
EPSS
Процентиль: 7%
0.00174
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-295