MEDIUM · 4.3

CVE-2013-7304

Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by pr...

Vulnerability Description

Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CheckpointEndpoint Security Mi Server R73<= 3.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-7304?

CVE-2013-7304 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by pr...

How severe is CVE-2013-7304?

CVE-2013-7304 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-7304?

Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Endpoint Security Mi Server R73.