CVE-2025-50944: High severity AVTECH EagleEyes vulnerability
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50944?
CVE-2025-50944 is considered a critical vulnerability due to its impact on SSL/TLS encryption.
How do I fix CVE-2025-50944?
To fix CVE-2025-50944, update to the latest version of AVTECH EagleEyes where the improper certificate validation is resolved.
What systems are affected by CVE-2025-50944?
CVE-2025-50944 affects AVTECH EagleEyes version 2.0.0 specifically.
What are the potential impacts of CVE-2025-50944?
The potential impacts of CVE-2025-50944 include increased vulnerability to man-in-the-middle attacks due to inadequate certificate validation.
Is there a workaround for CVE-2025-50944 if I can't update?
A possible workaround for CVE-2025-50944 includes implementing additional validation mechanisms for SSL certificates until an update can be applied.