SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2000-0406

Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the…

LOW 2.6EPSS 1.03%

Does this matter?

Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.

Description

Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Affected
netscape/communicator
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.