CVE Vulnerabilities

CVE-2016-7815

Improper Certificate Validation

Published: Apr 28, 2017 | Modified: May 10, 2017
CVSS 3.x
4.2
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Remote_service_manager Cybozu 3.0.0 (including) 3.0.0 (including)
Remote_service_manager Cybozu 3.0.1 (including) 3.0.1 (including)
Remote_service_manager Cybozu 3.1.0 (including) 3.1.0 (including)
Remote_service_manager Cybozu 3.1.1 (including) 3.1.1 (including)
Remote_service_manager Cybozu 3.1.2 (including) 3.1.2 (including)
Remote_service_manager Cybozu 3.1.3 (including) 3.1.3 (including)
Remote_service_manager Cybozu 3.1.4 (including) 3.1.4 (including)

Potential Mitigations

References