7.4
CVE-2018-5408
- EPSS 0.75%
- Veröffentlicht 08.05.2019 15:30:52
- Zuletzt bearbeitet 21.11.2024 04:08:45
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
PrinterLogic Print Management Software fails to validate the management portal SSL certificates
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Printerlogic ≫ Print Management Version <= 18.3.1.96
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.75% | 0.501 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.4 | 2.2 | 5.2 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
http://www.securityfocus.com/bid/108285
https://kb.cert.org/vuls/id/169249/