Key Exchange without Entity Authentication
CVE-2024-47519
Summary
Backup uploads to ETM subject to man-in-the-middle interception
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- LOW
CWE-322 - Key Exchange without Entity Authentication
The software performs a key exchange with an actor without verifying the identity of that actor.
References
Advisory Timeline
- Published