Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-39334
HistoryNov 25, 2022 - 12:00 a.m.

CVE-2022-39334 nextcloudcmd incorrectly trusts bad TLS certificates

2022-11-2500:00:00
CWE-295
GitHub_M
www.cve.org
5
nextcloudcmd
bad tls certificates
man-in-the-middle
cli
sensitive data
network attacker

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

20.4%

Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only. It does not affect the standard GUI desktop Nextcloud clients, and it does not affect the Nextcloud server.

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": "< 3.6.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

20.4%