CVE-2018-1000664
CVE-2018-1000664
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Sep 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim connects to a server that's MITM/Proxied by an attacker.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →