Netskope Threat Labs

FILE-JAVA ConnectWise CR Java ECDSA TLS Signature CVE-2022-21449

IPS-CFW

1 SID: 2036377

Detects TLS handshakes carrying the invalid ECDSA signature structure from CVE-2022-21449, the psychic signature flaw in Java that accepted forged signatures. The flaw let cyberattackers impersonate TLS servers that rely on Java's certificate validation.