CVE-2008-1113
Summary
| CVE | CVE-2008-1113 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-03 18:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 7921 Wireless Ip Phone | All | All | All | All |
| Application | Vocera Communications | Vocera Communications Badge | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco confirms vulnerability in 7921 Wi-Fi IP phone | Zero Day | ZDNet.com | af854a3a-2127-422b-91ae-364da2661108 | blogs.zdnet.com | |
| Full Disclosure: Cisco confirms vulnerability in 7921 Wi-Fi IP phone | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Cisco IP Phone 7921 Insecure PEAP Implementation - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: Cisco and Vocera wireless LAN VoIP devices don't check certificates | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Design flaw in wireless VoIP handsets endanger the enterprise | Zero Day | ZDNet.com | af854a3a-2127-422b-91ae-364da2661108 | blogs.zdnet.com | |
| SecurityTracker.com Archives - Cisco Unified Wireless IP Phone 7921 Does Not Validate Sever Certificates When Using PEAP | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.