Untriaged
Permalink
CVE-2026-1068
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): ADJACENT_NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
An improper certificate validation vulnerability was reported in the Lenovo …
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
References
Affected products
FileZ
- <10.12.3.0
- <11.1.0.35
Matching in nixpkgs
pkgs.filezilla
Graphical FTP, FTPS and SFTP client
Package maintainers
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>