5.9
CVSSv3

CVE-2014-2845

Published: 15/11/2017 Updated: 11/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cyberduck prior to 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle malicious users to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.

Vulnerable Product Search on Vulmon Subscribe to Product

cyberduck cyberduck

Exploits

Cyberduck version 443 (14140) for Windows fails to properly validate X509 certificates ...