CVE Vulnerabilities

CVE-2025-50944

Improper Certificate Validation

Published: Sep 15, 2025 | Modified: Oct 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificates expiration date, skipping proper TLS chain validation.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Eagleeyes(lite) Avtech 2.0.0 (including) 2.0.0 (including)

Potential Mitigations

References