CVE-2015-4094: Medium severity delinea pam secret server vulnerability
The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4094?
CVE-2015-4094 has a medium severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2015-4094?
To mitigate CVE-2015-4094, upgrade to a version of Thycotic Secret Server that validates X.509 certificates.
What are the risks associated with CVE-2015-4094?
The risks include the possibility of attackers spoofing SSL servers and intercepting sensitive information from users.
Which versions of Thycotic Secret Server are affected by CVE-2015-4094?
Thycotic Secret Server versions up to and including 2.3 for iOS are affected by CVE-2015-4094.
Can CVE-2015-4094 be exploited remotely?
Yes, CVE-2015-4094 can be exploited remotely by attackers able to present a crafted SSL certificate.