Impact
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows signature spoofing by failing to properly validate certificates. The flaw, classified as CWE‑295, enables an attacker to impersonate a trusted certificate and potentially log in as a legitimate user or bypass authentication that relies on proper certificate validation. This can be exploited by providing a forged certificate to the agent or otherwise manipulating the validation process.
Affected Systems
Affected by this flaw are Thales SafeNet Agent for Windows Logon versions 4.0.0, 4.1.1, and 4.1.2. Users running any of these releases on Windows are exposed to potential signature spoofing.
Risk and Exploitability
The CVSS score of 2.5 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a local or remote attacker with the capability to supply forged certificates to the agent. No specific intrusion prerequisites are described, but the flaw allows bypassing authentication mechanisms that rely on validated certificates.
OpenCVE Enrichment