CVE Vulnerabilities

CVE-2025-50944

Improper Certificate Validation

Published: Sep 15, 2025 | Modified: Sep 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificates expiration date, skipping proper TLS chain validation.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References