Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
History

Wed, 25 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 09:45:00 +0000

Type Values Removed Values Added
Description Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
Title Cyberduck and Mountain Duck - Improper Certificate Store Handling
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sba-research

Published: 2025-06-25T09:21:37.479Z

Updated: 2025-06-25T13:33:27.985Z

Reserved: 2025-04-16T09:37:50.630Z

Link: CVE-2025-41255

cve-icon Vulnrichment

Updated: 2025-06-25T13:33:19.194Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-25T10:15:21.783

Modified: 2025-06-26T18:58:14.280

Link: CVE-2025-41255

cve-icon Redhat

No data.