« Volver al listado

CVE-2014-0350

Estado: ModificadaMedia (6.4)—

The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0350",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-26T01:55:04.967",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177471.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177573.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/118748",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://raw.githubusercontent.com/pocoproject/poco/poco-1.4.6p4-release/CHANGELOG",
      "source": "cret@cert.org"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177471.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177573.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/118748",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://raw.githubusercontent.com/pocoproject/poco/poco-1.4.6p4-release/CHANGELOG",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PTR records that are requested during comparison of a server name to a wildcard domain name in an X.509 certificate."
    },
    {
      "lang": "es",
      "value": "El método Poco::Net::X509Certificate::verify en la libraría NetSSL en POCO C++ Libraries anterior a 1.4.6p4 permite a atacantes man-in-the-middle falsificar servidores SSL a través de registros DNS PTR manipulados que se solicitan durante comparación de un nombre de servidor hacia un nombre de dominio de comodín en un certificado X.509."
    }
  ],
  "lastModified": "2026-06-17T00:02:51.067",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pocoproject:poco_c\\+\\+_libraries:*:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A81841EA-4708-45B7-AF18-BBA98C575CAF",
              "versionEndIncluding": "1.4.6"
            },
            {
              "criteria": "cpe:2.3:a:pocoproject:poco_c\\+\\+_libraries:1.4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4B4E188-345E-4E04-BF98-15E2C823EE05"
            },
            {
              "criteria": "cpe:2.3:a:pocoproject:poco_c\\+\\+_libraries:1.4.6:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F30AC50-98E2-408E-AFCA-B11CA8975812"
            },
            {
              "criteria": "cpe:2.3:a:pocoproject:poco_c\\+\\+_libraries:1.4.6:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "570D8106-FD13-4695-A268-F2B15A398595"
            },
            {
              "criteria": "cpe:2.3:a:pocoproject:poco_c\\+\\+_libraries:1.4.6:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "193B5398-862A-465D-98DC-7DA3F55AC81D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}