ZeroHour

CVE-2020-8286

PoC
CVSS 3.1
7.5 high
EPSS
5%p91
Published
()
Modified
Description

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Vendors
haxxfedoraprojectdebiannetappapplesiemensoraclesplunk
Products
libcurl, fedora, debian linux, clustered data ontap, hci management node, solidfire, hci bootstrap os, hci storage node firmware, mac os x, macos, simatic tim 1531 irc firmware, sinec infrastructure network services
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.