CVE-2024-31854

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow an attacker to execute an on-path network (MitM) attack.
Configurations

No configuration.

History

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SICAM TOOLBOX II (todas las versiones anteriores a V07.11). Al establecer una conexión HTTPS con el servidor TLS de un dispositivo administrado, la aplicación afectada no compara el nombre común del certificado del dispositivo con el valor esperado. Esto podría permitir que un atacante ejecute un ataque de red en ruta (MitM).

08 Jul 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 11:15

Updated : 2025-07-08 16:18


NVD link : CVE-2024-31854

Mitre link : CVE-2024-31854

CVE.ORG link : CVE-2024-31854


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation