CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:C/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
77.0%
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | 7921_wireless_ip_phone | * | cpe:2.3:h:cisco:7921_wireless_ip_phone:*:*:*:*:*:*:*:* |
vocera_communications | vocera_communications_badge | * | cpe:2.3:a:vocera_communications:vocera_communications_badge:*:*:*:*:*:*:*:* |