Description
Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM).

This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-10-02
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Man‑in‑the‑Middle via improper TLS validation
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper validation of TLS certificates in HAVELSAN's Sef – AI Chatbot Platform, allowing an adversary in the middle (AiTM). Because the system does not verify certificates correctly, an attacker positioned between the client and server can present a forged or mis‑issued certificate and establish a man‑in‑the‑middle session. This allows the adversary to intercept, alter, or inject traffic without detection.

Affected Systems

The flaw affects all instances of Sef – AI Chatbot Platform running versions prior to 2.1. The product is distributed by HAVELSAN Inc. No specific component or sub‑module names appear in the data beyond the general API Tool Runner reference, and the precise CPE identifiers are not provided. Administrators should verify that their deployment is on an affected version.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity level, but the EPSS score is 0.00163, indicating a very low but nonzero exploitation probability. The vulnerability is not yet listed in CISA's KEV catalog, yet the nature of the flaw—allowing a man‑in‑the‑middle—means that an attacker with network access can exploit the issue remotely. The lack of published exploit codes does not reduce the risk, as the fundamental validation weakness can be abused with a few lines of scripting or a custom proxy.

Generated by OpenCVE AI on October 2, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Sef – AI Chatbot Platform to version 2.1 or later, which includes the proper TLS certificate validation logic.
  • Configure the platform to enforce strict hostname verification and reject self‑signed or expired certificates during the TLS handshake.
  • Apply network security controls such as TLS interception detection, traffic monitoring, and segmentation to detect and block potential man‑in‑the‑middle attempts.

Generated by OpenCVE AI on October 2, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan sef - Ai Chatbot Platform
Vendors & Products Havelsan
Havelsan sef - Ai Chatbot Platform

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1.
Title Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Havelsan Sef - Ai Chatbot Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-02T14:36:56.031Z

Reserved: 2026-08-26T11:27:31.565Z

Link: CVE-2026-80443

cve-icon Vulnrichment

Updated: 2026-10-02T13:33:38.935Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T09:16:44.823

Modified: 2026-10-02T15:17:10.993

Link: CVE-2026-80443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation