Back

CRITICAL

python-scciclient: missing server certificate verification

Published Sep 1, 2022

Description

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024
Reserved Aug 25, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 1, 2022
ENISA EUVD
Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-0408 GHSA-RF3F-3P37-2QH4