CVE Vulnerabilities

CVE-2019-8351

Improper Certificate Validation

Published: Mar 21, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
ThorHeimdalsecurity2.5.170-rc (including)2.5.170-rc (including)
ThorHeimdalsecurity2.5.171 (including)2.5.171 (including)
ThorHeimdalsecurity2.5.172 (including)2.5.172 (including)

Potential Mitigations

References