Velneo vClient Improper authentication
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.3epss 0.5%
probabilidade de exploração
0.5%top 61% das CVEs
exploração observada
nãonenhuma fonte reporta
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Produtos afetados
Velneo · Velneo vClientReferências
https://doc.velneo.com/v/29/velneo/notas-de-la-version#verificacion-de-certificadoshttps://velneo.es/publicacion-de-incidencia-de-seguridad-en-cve-cve-2021-45035/https://www.incibe-cert.es/en/early-warning/security-advisories/velneo-vclient-improper-authenticationhttps://www.velneo.com/blog/nueva-revision-velneo-29-2