Description
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions.
This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19096 | Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5. |
References
History
Wed, 25 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Jun 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5. | |
| Title | Cyberduck and Mountain Duck - Improper Certificate Store Handling | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2025-06-25T13:33:27.985Z
Reserved: 2025-04-16T09:37:50.630Z
Link: CVE-2025-41255
Updated: 2025-06-25T13:33:19.194Z
Status : Awaiting Analysis
Published: 2025-06-25T10:15:21.783
Modified: 2025-06-26T18:58:14.280
Link: CVE-2025-41255
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD