Описание
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.
EPSS
Процентиль: 0%
0.00074
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 6.1
github
около 2 месяцев назад
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.
EPSS
Процентиль: 0%
0.00074
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-295