Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Blunden

#44377de 53,635
5.9CVSS total
Vulnerabilidades · 1
PT-2017-10907
5.9
2017-11-17
Nvidia · Nv-Websocket-Client · CVE-2017-1000209
**Name of the Vulnerable Software and Affected Versions** nv-websocket-client (affected versions not specified) **Description** The issue concerns a failure to verify the server hostname against the domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL/TLS servers using any valid certificate. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.