Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
BID:60155
Info
Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 60155 |
| Class: | Design Error |
| CVE: |
CVE-2012-6399 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2013 12:00AM |
| Updated: | May 24 2013 12:00AM |
| Credit: | Charlie Eriksen via Secunia. |
| Vulnerable: |
Cisco WebEx for iOS 4.1 |
| Not Vulnerable: | |
Discussion
Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
Cisco WebEx for iOS is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers which will aid further attacks.
Cisco WebEx for iOS 4.1 is vulnerable; other versions may also be affected.
Cisco WebEx for iOS is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers which will aid further attacks.
Cisco WebEx for iOS 4.1 is vulnerable; other versions may also be affected.
Exploit / POC
Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco WebEx for iOS CVE-2012-6399 Certificate Validation Security Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- WebEx Homepage (Cisco)