CVE-2024-44097
CVSS V2 None
CVSS V3 None
Description
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."
Overview
- CVE ID
- CVE-2024-44097
- Assigner
- Google_Devices
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-02T14:06:33.704Z
- Last Modified Date
- 2024-10-02T17:00:33.323Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://support.google.com/product-documentation/answer/14950962?sjid=9489879942601373169-NA |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-44097 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44097 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 23:50:49 | Added to TrackCVE |