Description
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.
Problem types
CWE-295 – Improper Certificate Validation
Product status
24.9 (semver)
References
www.altium.com/...rm/security-compliance/security-advisories