Lucene search

K
nvd[email protected]NVD:CVE-2010-4211
HistoryNov 09, 2010 - 1:00 a.m.

CVE-2010-4211

2010-11-0901:00:02
CWE-287
web.nvd.nist.gov
2

CVSS2

2.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

35.5%

The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.

Affected configurations

Nvd
Node
ebaypaypalRange3.0
AND
appleiphone_osMatch3.1
OR
appleiphone_osMatch3.1.2
OR
appleiphone_osMatch3.1.3
VendorProductVersionCPE
ebaypaypal*cpe:2.3:a:ebay:paypal:*:*:*:*:*:*:*:*
appleiphone_os3.1cpe:2.3:o:apple:iphone_os:3.1:*:*:*:*:*:*:*
appleiphone_os3.1.2cpe:2.3:o:apple:iphone_os:3.1.2:*:*:*:*:*:*:*
appleiphone_os3.1.3cpe:2.3:o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*

CVSS2

2.9

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

35.5%

Related for NVD:CVE-2010-4211