CVE-2024-39771

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.
References
Link Resource
https://jvn.jp/en/jp/JVN83440451/ Third Party Advisory
https://safie.jp/information/post_6933/ Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:safie:qbic_cloud_cc-2\/2l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safie:qbic_cloud_cc-2\/2l:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:safie:safie_one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:safie:safie_one:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-28 06:15

Updated : 2024-10-28 21:35


NVD link : CVE-2024-39771

Mitre link : CVE-2024-39771

CVE.ORG link : CVE-2024-39771


JSON object : View

Products Affected

safie

  • qbic_cloud_cc-2\/2l_firmware
  • qbic_cloud_cc-2\/2l
  • safie_one
  • safie_one_firmware
CWE
CWE-295

Improper Certificate Validation