CVE-2021-3460

The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:mh702x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mh702x:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:21

Type Values Removed Values Added
References () https://motorolamentor.zendesk.com/hc/en-us/articles/1260804087249 - Vendor Advisory () https://motorolamentor.zendesk.com/hc/en-us/articles/1260804087249 - Vendor Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 8.1

Information

Published : 2021-04-13 21:15

Updated : 2024-11-21 06:21


NVD link : CVE-2021-3460

Mitre link : CVE-2021-3460

CVE.ORG link : CVE-2021-3460


JSON object : View

Products Affected

motorola

  • mh702x
  • mh702x_firmware
CWE
CWE-295

Improper Certificate Validation