CVE Vulnerabilities

CVE-2025-50944

Improper Certificate Validation

Published: Sep 15, 2025 | Modified: Oct 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificates expiration date, skipping proper TLS chain validation.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Eagleeyes(lite)Avtech2.0.0 (including)2.0.0 (including)

Potential Mitigations

References