Medium severity5.9NVD Advisory· Published Nov 15, 2017· Updated Jun 17, 2026
CVE-2014-2845
CVE-2014-2845
Description
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:cyberduck:cyberduck:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cyberduck:cyberduck:*:*:*:*:*:*:*:*range: <4.4.4
- (no CPE)range: <4.4.4
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/archive/1/532039/100/0/threadednvdExploitThird Party AdvisoryVDB Entry
- cyberduck.io/changelog/nvdIssue TrackingRelease NotesVendor Advisory
- secunia.com/advisories/58426nvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.