CVE-2019-14852
published 2021-03-18CVE-2019-14852: A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
35.0th percentile
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | 3scale_api_management | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apicast: deprecated protocol TLS 1.0 enabled in gateway
vendor_redhat·2021-03-17·CVSS 7.5
CVE-2019-14852 [HIGH] CWE-327 apicast: deprecated protocol TLS 1.0 enabled in gateway
apicast: deprecated protocol TLS 1.0 enabled in gateway
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information.
Package: apicast (Red Hat 3scale API Management Platform 2) - Affected
GHSA
GHSA-hpq5-x75j-q4f2: A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1
ghsa_unreviewed·2022-05-24
CVE-2019-14852 [HIGH] CWE-327 GHSA-hpq5-x75j-q4f2: A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.
No detection rules found.
No public exploits indexed.
2021-03-18
Published