← Back to CVE List

CVE-2024-44097

Published: 2024-10-02T14:15Z
Last Modified: 2024-10-04T13:50Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server." > MITRE Terms of Use apply – see LICENSE‑MITRE.txt