Security Advisory

CVE-2014-2845

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-15 18:00:00
Last updated 2024-08-06 10:28:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.