Improper Certificate Validation in AREAL Topkapi Vision (Server)
CVE-2023-50356

6.5MEDIUM

Key Information:

Vendor

AREAL SAS

Vendor
CVE Published:
31 January 2024

What is CVE-2023-50356?

SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.

Affected Version(s)

Topkapi Vision (Server) 0 <= 6.2.4718

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.