Beveiligingsadvies

CVE-2025-41255

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-06-25 09:21:37
Laatst bijgewerkt 2025-06-25 13:33:27
Toegewezen door sba-research
CVSS-score 8.0
Status PUBLISHED

Beschrijving

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.