Sony mylo COM-2 SSL Certificate Validation Vulnerability
BID:28905
Info
Sony mylo COM-2 SSL Certificate Validation Vulnerability
| Bugtraq ID: | 28905 |
| Class: | Design Error |
| CVE: |
CVE-2008-1938 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | This issue was disclosed via JVN. |
| Vulnerable: |
Sony Mylo COM-2 0 |
| Not Vulnerable: |
Sony Mylo COM-2 1.002 firmware |
Discussion
Sony mylo COM-2 SSL Certificate Validation Vulnerability
Sony mylo COM-2 devices are prone to a certificate-validation vulnerability because they fail to properly validate webserver certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted webservers. This will aid in further attacks.
This issue affects only the Japanese model of Sony mylo COM-2 devices running firmware versions prior to 1.002.
Sony mylo COM-2 devices are prone to a certificate-validation vulnerability because they fail to properly validate webserver certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted webservers. This will aid in further attacks.
This issue affects only the Japanese model of Sony mylo COM-2 devices running firmware versions prior to 1.002.
Exploit / POC
Sony mylo COM-2 SSL Certificate Validation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
Sony mylo COM-2 SSL Certificate Validation Vulnerability
References:
References:
- ?mylo COM-2 ?????????????????? ???????????????? (Sony)
- Sony Mylo COM-2 Product Page (Sony)
- JVN#76788395 (JVN)