4.3

CVE-2013-0289

Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Data is provided by the National Vulnerability Database (NVD)
Isync ProjectIsync Version0.4
Isync ProjectIsync Version0.5
Isync ProjectIsync Version0.6
Isync ProjectIsync Version0.7
Isync ProjectIsync Version0.8
Isync ProjectIsync Version1.0.0
Isync ProjectIsync Version1.0.1
Isync ProjectIsync Version1.0.2
Isync ProjectIsync Version1.0.3
Isync ProjectIsync Version1.0.4
Isync ProjectIsync Version1.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.62
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N