SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-5372

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which…

MEDIUM 5.0EPSS 0.87%

Does this matter?

Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.

Description

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.87% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
adnovum/nevisauth
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.