CVE-2023-25392 describes a Missing SSL Certificate Validation vulnerability in Allegro Tech BigFlow versions prior to 1.6. This medium-severity vulnerability (CVSS 5.9) allows an unauthenticated attacker to intercept sensitive data due to the application failing to properly validate SSL certificates, requiring high attack complexity. There is currently no evidence of active exploitation, nor is public exploit code available in Metasploit or ExploitDB. The vulnerability has received minimal community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6CPE matchmatch criteria | cpe:2.3:a:allegro:bigflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.