VulnerabilityModified
CVE-2014-0636
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.
MEDIUM 5.8EPSS 0.67%
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- dell/bsafe micro-edition-suite
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-04/0069.htmlBroken Link
- http://www.securityfocus.com/bid/66791Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-04/0069.htmlBroken Link
- http://www.securityfocus.com/bid/66791Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.