Vulnerability Details CVE-2015-0961
Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-0961
-
cpe:2.3:a:barracuda:web_filter:7.0
-
cpe:2.3:a:barracuda:web_filter:7.0.1
-
cpe:2.3:a:barracuda:web_filter:7.1.0
-
cpe:2.3:a:barracuda:web_filter:8.0
-
cpe:2.3:a:barracuda:web_filter:8.0.002
-
cpe:2.3:a:barracuda:web_filter:8.0.003