VYPR
Unrated severityNVD Advisory· Published Nov 18, 2019· Updated Aug 4, 2024

CVE-2019-5102

CVE-2019-5102

Description

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Openwrt/Openwrtllm-fuzzy2 versions
    = 18.06.4, = 15.05.1+ 1 more
    • (no CPE)range: = 18.06.4, = 15.05.1
    • (no CPE)range: OpenWrt 15.05.1, via wget (busybox)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.