CVE-2008-5124

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
jscapesecure_ftp_applet
𝑥
≤ 4.8.0
jscapesecure_ftp_applet
1.1
jscapesecure_ftp_applet
1.2
jscapesecure_ftp_applet
1.3
jscapesecure_ftp_applet
1.4
jscapesecure_ftp_applet
1.5
jscapesecure_ftp_applet
1.6
jscapesecure_ftp_applet
2.0
jscapesecure_ftp_applet
2.1
jscapesecure_ftp_applet
2.5
jscapesecure_ftp_applet
2.6
jscapesecure_ftp_applet
3.0
jscapesecure_ftp_applet
3.0.1
jscapesecure_ftp_applet
3.0.2
jscapesecure_ftp_applet
3.0.3
jscapesecure_ftp_applet
3.0.4
jscapesecure_ftp_applet
4.0
jscapesecure_ftp_applet
4.2.0
jscapesecure_ftp_applet
4.3.0
jscapesecure_ftp_applet
4.4.0
jscapesecure_ftp_applet
4.5.0
jscapesecure_ftp_applet
4.6.0
jscapesecure_ftp_applet
4.7
𝑥
= Vulnerable software versions