SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3285

jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.

MEDIUM 5.3EPSS 1.14%

Does this matter?

Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.

Description

jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
ti/code composer studio intgrated development environment
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.