Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encrypted connections to cleartext.
References
| Link | Resource |
|---|---|
| https://www.detack.de/en/cve-2019-6265-6266 | Mitigation Third Party Advisory |
| https://www.detack.de/en/cve-2019-6265-6266 | Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-25 23:29
Updated : 2024-11-21 04:46
NVD link : CVE-2019-6266
Mitre link : CVE-2019-6266
CVE.ORG link : CVE-2019-6266
JSON object : View
Products Affected
cordaware
- bestinformed
CWE
CWE-295
Improper Certificate Validation
