First published: Mon Apr 10 2023(Updated: )
Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/bigflow | <1.6.0 | 1.6.0 |
Allegro Bigflow | <1.6 | |
<1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25392 is considered a vulnerability of high severity due to its impact on SSL certificate validation.
To fix CVE-2023-25392, upgrade Allegro Tech BigFlow to version 1.6.0 or later.
CVE-2023-25392 affects all versions of Allegro Tech BigFlow prior to 1.6.0.
Exploitation of CVE-2023-25392 could allow an attacker to intercept and manipulate data due to the lack of SSL certificate validation.
There are no recommended workarounds for CVE-2023-25392; the only solution is to update to the fixed version.