QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN83440451/ | Third Party Advisory |
https://safie.jp/information/post_6933/ | Vendor Advisory |
Configurations
History
12 Sep 2024, 21:34
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
References | () https://jvn.jp/en/jp/JVN83440451/ - Third Party Advisory | |
References | () https://safie.jp/information/post_6933/ - Vendor Advisory | |
First Time |
Safie qbic Cloud Cc-2\/2l Firmware
Safie safie One Firmware Safie Safie safie One Safie qbic Cloud Cc-2\/2l |
|
CWE | CWE-295 | |
CPE | cpe:2.3:o:safie:safie_one_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:safie:qbic_cloud_cc-2\/2l_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:safie:qbic_cloud_cc-2\/2l:-:*:*:*:*:*:*:* cpe:2.3:h:safie:safie_one:-:*:*:*:*:*:*:* |
28 Aug 2024, 12:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Aug 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-28 06:15
Updated : 2024-10-28 21:35
NVD link : CVE-2024-39771
Mitre link : CVE-2024-39771
CVE.ORG link : CVE-2024-39771
JSON object : View
Products Affected
safie
- safie_one
- safie_one_firmware
- qbic_cloud_cc-2\/2l
- qbic_cloud_cc-2\/2l_firmware
CWE
CWE-295
Improper Certificate Validation