CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. Exploitation may require the attacker to be authenticated.
CVE
CVE-2024-39771
Severity
MEDIUM
CVSS
6.8
EPSS
0.12%
Original NVD Description
QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.