high · CVSS v3 7.4 · EPSS 0.00163
CVE-2026-80443
Improper certificate validation in HAVELSAN Inc. Sef AI Chatbot Platform allows Adversary in the Middle attacks. The flaw exists in versions
Overview
Improper certificate validation in HAVELSAN Inc. Sef AI Chatbot Platform allows Adversary in the Middle attacks. The flaw exists in versions prior to 2.1 and can enable attackers to intercept or tamper with communications.
Description
Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
Impact
Confidentiality: attackers can read encrypted traffic. Integrity: they can modify messages. Availability: not directly impacted. Defenders: system administrators and security teams managing the platform.
Remediation
Upgrade to version 2.1 or later. If upgrade is not possible, disable external TLS connections or enforce strict certificate validation via configuration. Monitor network traffic for TLS handshake anomalies.
Risk context
High severity (CVSS 7.4) but low EPSS (0.00163) indicates low likelihood of exploitation. Nonetheless, defenders should address promptly due to potential for sensitive data exposure.
Affected products
- HAVELSAN Sef AI Chatbot Platform 2.0
- HAVELSAN Sef AI Chatbot Platform 1.9
Scores
- Severity
- high
- CVSS v2
- 7.1
- CVSS v3
- 7.4
- CVSS v4
- —
- EPSS
- 0.00163