CVE-2022-2996
published 2022-09-01CVE-2022-2996: A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up…
PriorityP336high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.51%
40.6th percentile
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python-scciclient | < python-scciclient 0.12.3-2 (bookworm) | python-scciclient 0.12.3-2 (bookworm) |
| python-scciclient_project | python-scciclient | — | — |
| python-scciclient_project | python-scciclient | >= 0 < 0.12.3-2 | 0.12.3-2 |
| python-scciclient_project | python-scciclient | >= 0 < 0.12.3-2 | 0.12.3-2 |
| python-scciclient_project | python-scciclient | >= 0 < 0.12.3-2 | 0.12.3-2 |
| python-scciclient_project | python-scciclient | >= 0 < 0.12.0 | 0.12.0 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-scciclient: missing server certificate verification
vendor_redhat·2022-06-01·CVSS 7.4
CVE-2022-2996 [HIGH] CWE-295 python-scciclient: missing server certificate verification
python-scciclient: missing server certificate verification
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
Package: python-scciclient (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Debian
CVE-2022-2996: python-scciclient - A flaw was found in the python-scciclient when making an HTTPS connection to a s...
vendor_debian·2022·CVSS 7.4
CVE-2022-2996 [HIGH] CVE-2022-2996: python-scciclient - A flaw was found in the python-scciclient when making an HTTPS connection to a s...
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
Scope: local
bookworm: resolved (fixed in 0.12.3-2)
bullseye: open
forky: resolved (fixed in 0.12.3-2)
sid: resolved (fixed in 0.12.3-2)
trixie: resolved (fixed in 0.12.3-2)
OSV
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
osv·2022-09-02
CVE-2022-2996 [CRITICAL] python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
GHSA
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
ghsa·2022-09-02
CVE-2022-2996 [CRITICAL] CWE-295 python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
OSV
CVE-2022-2996: A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified
osv·2022-09-01·CVSS 7.4
CVE-2022-2996 [HIGH] CVE-2022-2996: A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/11/msg00006.htmlhttps://opendev.org/x/python-scciclient/commit/274dca0344b65b4ac113d3271d21c17e970a636chttps://lists.debian.org/debian-lts-announce/2022/11/msg00006.htmlhttps://opendev.org/x/python-scciclient/commit/274dca0344b65b4ac113d3271d21c17e970a636c
2022-09-01
Published