Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://blogs.zdnet.com/security/?p=896 - | |
References | () http://blogs.zdnet.com/security/?p=901 - | |
References | () http://seclists.org/fulldisclosure/2008/Feb/0402.html - | |
References | () http://seclists.org/fulldisclosure/2008/Feb/0449.html - | |
References | () http://secunia.com/advisories/29082 - Vendor Advisory | |
References | () http://securitytracker.com/id?1019494 - | |
References | () http://www.securityfocus.com/bid/27935 - |
Information
Published : 2008-03-03 18:44
Updated : 2024-11-21 00:43
NVD link : CVE-2008-1113
Mitre link : CVE-2008-1113
CVE.ORG link : CVE-2008-1113
JSON object : View
Products Affected
vocera_communications
- vocera_communications_badge
cisco
- 7921_wireless_ip_phone
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor