Impact
The vulnerability is an improper validation of TLS certificates in HAVELSAN's Sef – AI Chatbot Platform, allowing an adversary in the middle (AiTM). Because the system does not verify certificates correctly, an attacker positioned between the client and server can present a forged or mis‑issued certificate and establish a man‑in‑the‑middle session. This allows the adversary to intercept, alter, or inject traffic without detection.
Affected Systems
The flaw affects all instances of Sef – AI Chatbot Platform running versions prior to 2.1. The product is distributed by HAVELSAN Inc. No specific component or sub‑module names appear in the data beyond the general API Tool Runner reference, and the precise CPE identifiers are not provided. Administrators should verify that their deployment is on an affected version.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity level, but the EPSS score is 0.00163, indicating a very low but nonzero exploitation probability. The vulnerability is not yet listed in CISA's KEV catalog, yet the nature of the flaw—allowing a man‑in‑the‑middle—means that an attacker with network access can exploit the issue remotely. The lack of published exploit codes does not reduce the risk, as the fundamental validation weakness can be abused with a few lines of scripting or a custom proxy.
OpenCVE Enrichment