Vulnerability Description
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webroot | Brightcloud | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0686Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0686Third Party Advisory
FAQ
What is CVE-2018-4015?
CVE-2018-4015 is a vulnerability with a CVSS score of 8.1 (HIGH). An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in ...
How severe is CVE-2018-4015?
CVE-2018-4015 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-4015?
Check the references section above for vendor advisories and patch information. Affected products include: Webroot Brightcloud.