Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
BID:27935
Info
Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
| Bugtraq ID: | 27935 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1114 CVE-2008-1113 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | George Ou disclosed this issue. |
| Vulnerable: |
Vocera Communications Vocera Communications Badge 0 Cisco Wireless IP Phone 7921 0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
Multiple VoIP products are prone to a security-bypass vulnerability in their PEAP implementation because their software fails to properly validate server certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted authentication servers. This will aid in further attacks.
The following products are prone to this issue:
- Vocera Communications System badges
- Cisco Wireless IP Phone 7921
Other devices and packages may also be affected.
Multiple VoIP products are prone to a security-bypass vulnerability in their PEAP implementation because their software fails to properly validate server certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted authentication servers. This will aid in further attacks.
The following products are prone to this issue:
- Vocera Communications System badges
- Cisco Wireless IP Phone 7921
Other devices and packages may also be affected.
Exploit / POC
Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Vendor PEAP Certificate Verification Security Bypass Vulnerability
References:
References:
- [Full-disclosure] Cisco and Vocera wireless LAN VoIP devices don't check certifi (George Ou)
- [Full-disclosure] Cisco confirms vulnerability in 7921 Wi-Fi IP phone (George Ou)
- Cisco confirms vulnerability in 7921 Wi-Fi IP phone (ZDNet)
- Design flaw in wireless VoIP handsets endanger the enterprise (ZDNet)
- Vocera Communications Home Page (Vocera Communications)