Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-01-16T21:19:22.701Z
Reserved: 2012-05-30T00:00:00.000Z
Link: CVE-2012-2993
Updated: 2024-08-06T19:50:05.344Z
Status : Deferred
Published: 2012-09-18T03:48:28.507
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-2993
No data.
OpenCVE Enrichment
No data.
Weaknesses