Pantech Link Phones Browser Certificate Verification Security Weakness
BID:49755
Info
Pantech Link Phones Browser Certificate Verification Security Weakness
| Bugtraq ID: | 49755 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2011 12:00AM |
| Updated: | Sep 23 2011 12:00AM |
| Credit: | Trustwave |
| Vulnerable: |
Pantech Link P7040P 0 |
| Not Vulnerable: | |
Discussion
Pantech Link Phones Browser Certificate Verification Security Weakness
The browser of Pantech Link Phones is prone to a security weakness because it fails to verify SSL certificates presented by a remote server.
An attacker can exploit this weakness to masquerade as a legitimate server using a man-in-the-middle attack or to launch other attacks, such as phishing.
The browser of Pantech Link Phones is prone to a security weakness because it fails to verify SSL certificates presented by a remote server.
An attacker can exploit this weakness to masquerade as a legitimate server using a man-in-the-middle attack or to launch other attacks, such as phishing.
Exploit / POC
Pantech Link Phones Browser Certificate Verification Security Weakness
An attacker use readily available tools to carry out this attack.
An attacker use readily available tools to carry out this attack.
Solution / Fix
Pantech Link Phones Browser Certificate Verification Security Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Pantech Link Phones Browser Certificate Verification Security Weakness
References:
References:
- Pantech Link Product Page (Pantech)
- Vulnerability in Pantech Web Browser SSL Implementation (Trustwave)