CVE Published: 31/01/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: CERTVDE |
Vendor: AREAL SAS |
Product: Topkapi Vision (Server) Status : PUBLISHED
CVE-2023-50356 Description
SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L