9.8
CVE-2019-6266
- EPSS 0.26%
- Veröffentlicht 25.02.2019 23:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encrypted connections to cleartext.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cordaware ≫ Bestinformed SwPlatformwindows Version < 6.2.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.49 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.