CVE-2021-45035

MEDIUM

Velneo vClient 28.1.3 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.

Scores

CVSS v3 6.3
EPSS 0.0036
EPSS Percentile 27.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-295
Status published
Products (1)
velneo/vclient 28.1.3
Published Sep 23, 2022
Tracked Since Feb 18, 2026