CVE-2024-39771: Safie Qbic Cloud Cc-2/2l Firmware

Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communications of the affected product via a man-in-the-middle attack.

Affected products

  • Safie Qbic Cloud Cc-2/2l Firmware: up to and including 1.1.30
  • Safie Safie One Firmware: up to and including 1.8.2

Published 2024-08-28. Last modified 2026-06-17.