Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97696
HistoryDec 13, 2023 - 12:00 a.m.

Zammad Trust Management Issues Vulnerabilities

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
zammad
trust management
vulnerability
ssl/tls
hostname validation
certificate authority
man-in-the-middle attack
cnvd

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%

Zammad is a suite of ticket management software from the German company Zammad. A trust management issue vulnerability exists in Zammad that stems from the fact that SSL/TLS is used in multiple subsystems to establish connections to external services without properly validating the hostname and certificate authority, which could be exploited by an attacker to cause a man-in-the-middle attack.

CPENameOperatorVersion
zammad zammadeq6.1.0

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%

Related for CNVD-2023-97696