Lucene search

K
cveCiscoCVE-2013-1228
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1228

2022-10-0316:14:48
CWE-310
cisco
web.nvd.nist.gov
29
cisco
jabber
ssl
certificates
man-in-the-middle
attack
cve-2013-1228

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

20.6%

Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.

Affected configurations

Nvd
Node
ciscojabberMatch--windows
VendorProductVersionCPE
ciscojabber-cpe:/a:cisco:jabber:-:-::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

20.6%

Related for CVE-2013-1228