Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thor | Heimdalsecurity | 2.5.170-rc (including) | 2.5.170-rc (including) |
Thor | Heimdalsecurity | 2.5.171 (including) | 2.5.171 (including) |
Thor | Heimdalsecurity | 2.5.172 (including) | 2.5.172 (including) |