Nextcloud Desktop < 3.14.2 - Improper Certificate Validation
Title source: ruleDescription
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Exploits (1)
References (4)
Scores
CVSS v3
4.2
EPSS
0.0041
EPSS Percentile
61.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Lab Environment
Details
CWE
CWE-295
Status
published
Products (1)
nextcloud/desktop
3.0.0 - 3.14.2
Published
Nov 15, 2024
Tracked Since
Feb 18, 2026