TROYANOSYVIRUS
Back to CVEs

CVE-2014-8155

N/A

Description

GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

CVE Details

CVSS v3.1 ScoreN/A
Published8/14/2015
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

gnu:gnutls

Weaknesses (CWE)

CWE-17

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.