Spoofing Vulnerability for Cyberduck

description-logoDescription

Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.

affected-products-logoAffected Applications

Cyberduck

CVE References

CVE-2014-2845