PT-2020-8077 · Suse · Suse Studio

Johannes Segitz

·

Published

2020-01-27

·

Updated

2020-02-04

·

CVE-2017-14806

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SUSE Studio onsite susestudio-common versions 1.3.17-56.6.3 and prior versions.
Description: The issue is related to an Improper Certificate Validation vulnerability, allowing remote attackers to perform a man-in-the-middle (MITM) attack on connections to the repositories. This enables the modification of packages received over these connections.
Recommendations: For SUSE Studio onsite susestudio-common versions 1.3.17-56.6.3 and prior versions, update to a version newer than 1.3.17-56.6.3 to resolve the issue. As a temporary workaround, consider restricting access to the repositories to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14806

Affected Products

Suse Studio