HCL AppScan Source <= 10.6 Improper Certificate Validation (CVE-2024-30149)

medium Nessus Plugin ID 300254

Synopsis

An application installed on the remote Windows host is affected by an improper certificate validation vulnerability.

Description

The version of HCL AppScan Source installed on the remote Windows host is 10.6.0 or earlier. It is, therefore, affected by an improper certificate validation vulnerability. HCL AppScan Source does not properly validate a TLS/SSL certificate for an executable, which could allow an attacker to perform a man-in-the-middle attack to intercept or modify traffic.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to HCL AppScan Source version 10.7.0 or later.

See Also

http://www.nessus.org/u?8310d7d2

Plugin Details

Severity: Medium

ID: 300254

File Name: hcl_appscan_source_CVE-2024-30149.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 3/2/2026

Updated: 3/2/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2024-30149

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Vulnerability Information

CPE: cpe:/a:hcltech:appscan_source

Required KB Items: installed_sw/HCL AppScan Source

Patch Publication Date: 10/31/2024

Vulnerability Publication Date: 10/31/2024

Reference Information

CVE: CVE-2024-30149

IAVB: 2024-B-0166