Nvidia · Nv-Websocket-Client · CVE-2017-1000209
**Name of the Vulnerable Software and Affected Versions**
nv-websocket-client (affected versions not specified)
**Description**
The issue concerns a failure to verify the server hostname against the domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL/TLS servers using any valid certificate.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.