PT-2024-28667 · Qbic · Qbic Cloud Cc-2L

·

CVE-2024-39771

·

Published

2024-08-27

·

Updated

2024-10-28

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions QBiC CLOUD CC-2L versions 1.1.30 and earlier Safie One versions 1.8.2 and earlier
Description The issue is related to improper certificate validation, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.
Recommendations For QBiC CLOUD CC-2L versions 1.1.30 and earlier, update to a version that properly validates certificates. For Safie One versions 1.8.2 and earlier, update to a version that properly validates certificates. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39771

Affected Products

Qbic Cloud Cc-2L