CVE-2025-56231
BaseFortify
Publication date: 2025-11-05
Last updated on: 2025-11-06
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tonec | internet_download_manager | 6.42.41.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Tonec Internet Download Manager 6.42.41.1 and earlier is due to missing SSL certificate validation. This means the software does not properly verify the authenticity of SSL certificates during updates, allowing attackers to bypass update protections and potentially deliver malicious updates.
How can this vulnerability impact me? :
An attacker could exploit this vulnerability to bypass update protections and deliver malicious updates to the software. This could lead to unauthorized code execution, compromise of the system running the software, or other security breaches.