Security Advisory

CVE-2018-4015

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-12-18 14:00:00
Last updated 2024-08-05 05:04:28
Assigner talos
State PUBLISHED

Description

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by default, resulting in a failure to validate TLS certificates. An attacker could impersonate a remote BrightCloud server to exploit this vulnerability.