PT-2017-10718 · Txaws · Txaws

Exarkun

·

Published

2017-07-13

·

Updated

2022-05-17

·

CVE-2017-1000007

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions txAWS (all current versions)
Description The issue is related to incomplete certificate verification, making txAWS susceptible to Man-in-the-Middle (MitM) attacks and potentially leading to information disclosure. This affects the security of data transmission, as an attacker could intercept and alter data without being detected.
Recommendations For all current versions, consider implementing additional certificate validation mechanisms to ensure complete verification and mitigate the risk of MitM attacks. As a temporary workaround, restrict access to sensitive data and consider using alternative secure communication protocols until a comprehensive fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000007
GHSA-CGGM-52QP-WVW7
PYSEC-2017-85

Affected Products

Txaws