8.8
CVE-2025-50944
- EPSS 0.04%
- Veröffentlicht 15.09.2025 00:00:00
- Zuletzt bearbeitet 14.10.2025 19:41:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avtech ≫ Eagleeyes(lite) Version2.0.0 SwPlatformandroid
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.131 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.