CVE-2022-2996

high

Description

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

References

https://opendev.org/x/python-scciclient/commit/274dca0344b65b4ac113d3271d21c17e970a636c

https://lists.debian.org/debian-lts-announce/2022/11/msg00006.html

Details

Source: Mitre, NVD

Published: 2022-09-01

Updated: 2022-12-12

Risk Information

CVSS v2

Base Score: 7.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: High