5.8

CVE-2014-3577

Exploit

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

Data is provided by the National Vulnerability Database (NVD)
ApacheHttpclient Version >= 4.0 <= 4.3.4
ApacheHttpasyncclient Version >= 4.0 <= 4.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.37% 0.796
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
http://seclists.org/fulldisclosure/2014/Aug/48
Third Party Advisory
Exploit
Mailing List
http://www.securityfocus.com/bid/69258
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1030812
Third Party Advisory
VDB Entry