Description

Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.

INFO

Published Date :

2025-06-25T09:16:58.586Z

Last Modified :

2025-06-25T13:34:07.242Z

Source :

sba-research
AFFECTED PRODUCTS

The following products are affected by CVE-2025-41256 vulnerability.

No data.

REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact