PT-2024-14309 · Ylianst · Ylianst Meshcentral

Kelsey Tian

·

Published

2024-01-30

·

Updated

2024-02-05

·

CVE-2023-51837

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ylianst MeshCentral version 1.1.16
Description The issue concerns missing SSL certificate validation.
Recommendations For Ylianst MeshCentral version 1.1.16, consider implementing proper SSL certificate validation to mitigate the risk of exploitation. As a temporary workaround, restrict access to sensitive resources until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2023-51837
GHSA-8XW6-9H78-C89J

Affected Products

Ylianst Meshcentral