HIGH🇵🇱 Wersja polska

CVE-2018-4015

CVSS 8.1v3.1pub. 2018-12-18upd. 2024-11-21

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Webroot Brightcloud

    APP
    Webroot
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-4012CRITICAL9.0PL ✓same product

Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP

CVE-2024-7826CRITICAL9.8PL ✓same vendor

Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności

CVE-2024-7825CRITICAL9.8PL ✓same vendor

Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji

CVE-2024-7824CRITICAL9.8PL ✓same vendor

Type Confusion w Webroot SecureAnywhere Web Shield umożliwia nadużycie funkcjonalności

CVE-2020-5754CRITICAL9.1PL ✓same vendor

Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash