WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-04-21T14:00:00
Updated: 2024-08-06T10:21:36.023Z
Reserved: 2014-04-08T00:00:00
Link: CVE-2014-2735
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-04-22T13:06:29.853
Modified: 2024-11-21T02:06:51.593
Link: CVE-2014-2735
Redhat
No data.