QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2...
Moderate severity
Unreviewed
Published
Aug 28, 2024
to the GitHub Advisory Database
•
Updated Sep 13, 2024
Description
Published by the National Vulnerability Database
Aug 28, 2024
Published to the GitHub Advisory Database
Aug 28, 2024
Last updated
Sep 13, 2024
QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.
References