CVE-2018-5408
Last modified
CVE-2018-5408 is a vulnerability of currently unknown severity. The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Printerlogic | Print Management | <= 18.3.1.96 |
References
- https://kb.cert.org/vuls/id/169249/Third Party Advisory, US Government Resource
- https://kb.cert.org/vuls/id/169249/Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5408?
How severe is CVE-2018-5408?
How do I fix CVE-2018-5408?
Are you affected by CVE-2018-5408?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
