CVE Vulnerabilities

CVE-2025-0500

Improper Certificate Validation

Published: Jan 15, 2025 | Modified: Jan 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References