AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-6422

MEDIUM · CVSS 4 EPSS 2.76%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-12-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-6422
Severity
MEDIUM
CVSS
4
EPSS
2.76%

Original NVD Description

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.