Feb. 16, 2023, 4:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. In the case of a successful man in the middle attack on magritte-ftp, an attacker would be able to read and modify network …

abuse api attack case certificates communications cve ftp intercept malicious man-in-the-middle .net network privileged service ssl tls tls certificates

Sr. Product Manager

@ MixMode | Remote, US

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Analysis Senior Specialist

@ NTT DATA | singapore, 01, SG

Information Assurance Analyst - Security Architecture / Vulnerability Management

@ Hawaiian Electric | Honolulu, Hawaii (HI), US, 96840