CVE-2008-1113
Summary
| CVE | CVE-2008-1113 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-03 18:44:00 UTC |
| Updated | 2008-09-05 21:36:00 UTC |
| Description | Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 7921 Wireless Ip Phone | All | All | All | All |
| Hardware | Cisco | 7921 Wireless Ip Phone | All | All | All | All |
| Application | Vocera Communications | Vocera Communications Badge | All | All | All | All |
| Application | Vocera Communications | Vocera Communications Badge | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Cisco Unified Wireless IP Phone 7921 Does Not Validate Sever Certificates When Using PEAP | SECTRACK | securitytracker.com | |
| Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability | BID | www.securityfocus.com | |
| Cisco confirms vulnerability in 7921 Wi-Fi IP phone | Zero Day | ZDNet.com | MISC | blogs.zdnet.com | |
| Cisco IP Phone 7921 Insecure PEAP Implementation - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Design flaw in wireless VoIP handsets endanger the enterprise | Zero Day | ZDNet.com | MISC | blogs.zdnet.com | |
| Full Disclosure: Cisco confirms vulnerability in 7921 Wi-Fi IP phone | FULLDISC | seclists.org | |
| Full Disclosure: Cisco and Vocera wireless LAN VoIP devices don't check certificates | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.