An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HWebroot Brightcloud
APPWebrootwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2018-4012CRITICAL9.0PL ✓ten sam produkt
Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP
CVE-2024-7826CRITICAL9.8PL ✓ten sam vendor
Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności
CVE-2024-7825CRITICAL9.8PL ✓ten sam vendor
Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji
CVE-2024-7824CRITICAL9.8PL ✓ten sam vendor
Type Confusion w Webroot SecureAnywhere Web Shield umożliwia nadużycie funkcjonalności
CVE-2020-5754CRITICAL9.1PL ✓ten sam vendor
Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash